Cisco Webex Meetings vulnerabilities
46 known vulnerabilities affecting cisco/cisco_webex_meetings.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM38
Vulnerabilities
Page 1 of 3
CVE-2026-20184P2CRITICALCVSS 9.8v39.7.7v39.9+54 more2026-04-15
CVE-2026-20184 [CRITICAL] CWE-295 CVE-2026-20184: A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service.
This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited t
nvd
CVE-2022-20763P3HIGHCVSS 8.8vn/a2022-04-06
CVE-2022-20763 [HIGH] CWE-502 CVE-2022-20763: A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authent
A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java code. This vulnerability is due to improper deserialization of Java code within login requests. An attacker could exploit this vulnerability by sending malicious login requests to the Cisco Webex Meetings
nvd
CVE-2020-3142P3HIGHCVSS 7.5vearlier than 39.11.5vearlier than 40.1.32020-01-26
CVE-2020-3142 [HIGH] CWE-284 CVE-2020-3142: A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allo
A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a Webex mobile application for either iOS or Android. The vulnerability is due to unintended meeti
nvd
CVE-2020-3194P3HIGHCVSS 7.8vn/a2020-04-15
CVE-2020-3194 [HIGH] CWE-119 CVE-2020-3194: A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the
nvd
CVE-2021-1502P3HIGHCVSS 7.8vn/a2021-06-04
CVE-2021-1502 [HIGH] CWE-119 CVE-2021-1502: A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player
A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. The vulnerability is due to insufficient validation of values within Webex recording files formatted as either Advanced Recording Format (ARF) or Webex Recordi
nvd
CVE-2021-1503P3HIGHCVSS 7.8vn/a2021-06-04
CVE-2021-1503 [HIGH] CWE-119 CVE-2021-1503: A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player
A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in either Advanced Recording Format (ARF) or Webex Recording F
nvd
CVE-2021-1526P3HIGHCVSS 7.8vn/a2021-06-04
CVE-2021-1526 [HIGH] CWE-119 CVE-2021-1526: A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbit
A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious WRF file through
nvd
CVE-2020-3440P3MEDIUMCVSS 6.5vn/a2020-08-26
CVE-2020-3440 [MEDIUM] CWE-22 CVE-2020-3440: A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remo
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remote attacker to overwrite arbitrary files on an end-user system. The vulnerability is due to improper validation of URL parameters that are sent from a website to the affected application. An attacker could exploit this vulnerability by persuading a user
nvd
CVE-2021-34743P4HIGHCVSS 7.1vn/a2021-10-21
CVE-2021-34743 [HIGH] CWE-352 CVE-2021-34743: A vulnerability in the application integration feature of Cisco Webex Software could allow an unauth
A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of cross-site request forgery (CSRF) tokens. An attacker
nvd
CVE-2026-20219P4MEDIUMCVSS 5.4v39.10v39.11+27 more2026-05-06
CVE-2026-20219 [MEDIUM] CWE-639 CVE-2026-20219: A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker
A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users or affect quiz and poll results. Cisco has addressed this vulnerability in Cisco Slido and no customer action is needed.
This vulnerability existed because of the presence of an insecure direct object re
nvd
CVE-2023-20134P4MEDIUMCVSS 6.5vn/a2023-04-05
CVE-2023-20134 [MEDIUM] CWE-20 CVE-2023-20134: Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated,
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3542P4MEDIUMCVSS 5.3vn/a2020-09-04
CVE-2020-3542 [MEDIUM] CWE-20 CVE-2020-3542: A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a pass
A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeting without providing the meeting password. The vulnerability is due to improper validation of input to API requests that are a part of meeting join flow. An attacker could exploit this vulnerability by sending an API request to the ap
nvd
CVE-2021-40128P4MEDIUMCVSS 5.3vn/a2021-11-04
CVE-2021-40128 [MEDIUM] CWE-183 CVE-2021-40128: A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthentic
A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by sen
nvd
CVE-2019-15960P4MEDIUMCVSS 5.4≥ unspecified, < n/a2019-11-26
CVE-2019-15960 [MEDIUM] CWE-264 CVE-2019-15960: A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an aut
A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit this vulnerability, the attacker must be logged in as a low-level administrator. The vulnerability is due to insufficient access control validation. An a
nvd
CVE-2022-20778P4MEDIUMCVSS 6.1vn/a2022-04-21
CVE-2022-20778 [MEDIUM] CWE-79 CVE-2022-20778: A vulnerability in the authentication component of Cisco Webex Meetings could allow an unauthenticat
A vulnerability in the authentication component of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the authentication component of Cisc
nvd
CVE-2022-20654P4MEDIUMCVSS 6.1v39.7.7v39.9+16 more2024-11-15
CVE-2022-20654 [MEDIUM] CWE-80 CVE-2022-20654: A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticat
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based interface of Cisco Webex Meetings. An attacker could e
nvd
CVE-2025-20291P4MEDIUMCVSS 6.1vN/A2025-09-03
CVE-2025-20291 [MEDIUM] CWE-601 CVE-2025-20291: A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to re
A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed.
This vulnerability existed because of insufficient validation of URLs that wer
nvd
CVE-2022-20852P4MEDIUMCVSS 6.5vn/a2022-08-10
CVE-2022-20852 [MEDIUM] CWE-1021 CVE-2022-20852: Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2026-20149P4MEDIUMCVSS 6.1vN/A2026-03-04
CVE-2026-20149 [MEDIUM] CWE-79 CVE-2026-20149: A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a c
A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability, and no customer action is needed.
This vulnerability was due to improper filtering of user-supplied input. Prior to this vulnerability being addressed, an attacker could have exp
nvd
CVE-2026-20233P4MEDIUMCVSS 6.1v39.7.7v39.9+54 more2026-06-03
CVE-2026-20233 [MEDIUM] CWE-79 CVE-2026-20233: A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauth
A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed.
This vulnerability existed because of insufficient validation of user in
nvd
1 / 3Next →