cbcvebase.

Apache Openmeetings vulnerabilities

29 known vulnerabilities affecting apache/openmeetings.

Total CVEs
29
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH15MEDIUM9

Vulnerabilities

Page 2 of 2
CVE-2017-7684P4HIGHCVSS 7.5v1.0.0v2.0+19 more2017-07-17
CVE-2017-7684 [HIGH] CWE-400 CVE-2017-7684: Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a de Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files to the server.
nvd
CVE-2016-2163P4MEDIUMCVSS 6.1≤ 3.1.02016-04-11
CVE-2016-2163 [MEDIUM] CWE-79 CVE-2016-2163: Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.
nvd
CVE-2017-7666P4HIGHCVSS 8.8v1.0.0v2.0+19 more2017-07-17
CVE-2017-7666 [HIGH] CWE-79 CVE-2017-7666: Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, c Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.
nvd
CVE-2018-1286P4MEDIUMCVSS 6.5≥ 3.0.0, ≤ 4.0.12018-02-28
CVE-2018-1286 [MEDIUM] CWE-287 CVE-2018-1286: In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.
nvd
CVE-2023-28936P4MEDIUMCVSS 5.3≥ 2.0.0, < 7.1.02023-05-12
CVE-2023-28936 [MEDIUM] CWE-697 CVE-2023-28936: Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affec Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
nvd
CVE-2016-3089P4MEDIUMCVSS 6.1≤ 3.1.12016-08-19
CVE-2016-3089 [MEDIUM] CWE-79 CVE-2016-3089: Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the swf parameter.
nvd
CVE-2017-7663P4MEDIUMCVSS 6.1v3.2.0v3.2.12017-07-17
CVE-2017-7663 [MEDIUM] CWE-79 CVE-2017-7663: Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.
nvd
CVE-2017-7685P4MEDIUMCVSS 5.3v1.0.0v2.0+19 more2017-07-17
CVE-2017-7685 [MEDIUM] CVE-2017-7685: Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PA Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.
nvd
CVE-2026-33005P4MEDIUMCVSS 4.3≥ 3.1.0, < 9.0.02026-04-09
CVE-2026-33005 [MEDIUM] CWE-274 CVE-2026-33005: Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered u Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object. This issue af
nvd
Apache Openmeetings vulnerabilities | cvebase