cbcvebase.

Cisco Webex Meetings vulnerabilities

46 known vulnerabilities affecting cisco/cisco_webex_meetings.

Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM38

Vulnerabilities

Page 2 of 3
CVE-2020-3472P4MEDIUMCVSS 5.0vn/a2020-08-17
CVE-2020-3472 [MEDIUM] CWE-200 CVE-2020-3472: A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within user contacts. An attacker on one Webex Meetings site could exploit this vulnerability by se
nvd
CVE-2020-27126P4MEDIUMCVSS 6.1vn/a2020-11-18
CVE-2020-27126 [MEDIUM] CWE-80 CVE-2020-27126: A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of user-supplied input to an application programmatic interface (API) within Cisco Webex Meetings. An attacker could exploit this vulnerability by convincing a targe
nvd
CVE-2020-3463P4MEDIUMCVSS 6.1vn/a2020-08-17
CVE-2020-3463 [MEDIUM] CWE-79 CVE-2020-3463: A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthe A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the web-based management
nvd
CVE-2021-1351P4MEDIUMCVSS 6.1vn/a2021-02-17
CVE-2021-1351 [MEDIUM] CWE-80 CVE-2021-1351: A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, r A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected service
nvd
CVE-2025-20246P4MEDIUMCVSS 6.1vN/A2025-05-21
CVE-2025-20246 [MEDIUM] CWE-79 CVE-2025-20246: A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-si A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to conduct a cro
nvd
CVE-2025-20247P4MEDIUMCVSS 6.1vN/A2025-05-21
CVE-2025-20247 [MEDIUM] CWE-79 CVE-2025-20247: A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-si A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to conduct a cro
nvd
CVE-2025-20250P4MEDIUMCVSS 6.1vN/A2025-05-21
CVE-2025-20250 [MEDIUM] CWE-79 CVE-2025-20250: A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-si A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to conduct a cro
nvd
CVE-2023-20133P4MEDIUMCVSS 5.4v39.10v39.11+30 more2023-07-07
CVE-2023-20133 [MEDIUM] CWE-79 CVE-2023-20133: A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote at A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email templates, and survey questions.
nvd
CVE-2025-20328P4MEDIUMCVSS 5.4vN/A2025-09-03
CVE-2025-20328 [MEDIUM] CWE-79 CVE-2025-20328: A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenti A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vuln
nvd
CVE-2025-20215P4MEDIUMCVSS 5.4vN/A2025-08-06
CVE-2025-20215 [MEDIUM] CWE-295 CVE-2025-20215: A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unau A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite conditions were satisfied. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no cust
nvd
CVE-2021-1410P4MEDIUMCVSS 4.3v39.7.7v39.9+16 more2024-11-18
CVE-2021-1410 [MEDIUM] CWE-284 CVE-2021-1410: A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authent A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An attacker could exploit this vulnerabili
nvd
CVE-2021-1527P4MEDIUMCVSS 6.1vn/a2021-06-04
CVE-2021-1527 [MEDIUM] CWE-119 CVE-2021-1527: A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to cause the aff A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to cause the affected software to terminate or to gain access to memory state information that is related to the vulnerable application. The vulnerability is due to insufficient validation of values in Webex recording files that are stored in Webex Recording Format (WR
nvd
CVE-2023-20132P4MEDIUMCVSS 5.4vn/a2023-04-05
CVE-2023-20132 [MEDIUM] CWE-20 CVE-2023-20132: Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1544P4MEDIUMCVSS 5.5vn/a2021-06-04
CVE-2021-1544 [MEDIUM] CWE-497 CVE-2021-1544: A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authent A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit this vulnerability by logging onto the local system and accessing files containing the logged d
nvd
CVE-2022-20820P4MEDIUMCVSS 5.4vn/a2022-08-10
CVE-2022-20820 [MEDIUM] CWE-1021 CVE-2022-20820: Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1467P4MEDIUMCVSS 4.3vn/a2021-04-08
CVE-2021-1467 [MEDIUM] CWE-284 CVE-2021-1467: A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they ar
nvd
CVE-2020-3412P4MEDIUMCVSS 4.3vn/a2020-08-17
CVE-2020-3412 [MEDIUM] CWE-284 CVE-2020-3412: A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an aut A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of scheduled meeting templates. An attacker c
nvd
CVE-2020-3413P4MEDIUMCVSS 4.3vn/a2020-08-17
CVE-2020-3413 [MEDIUM] CWE-284 CVE-2020-3413: A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an aut A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is due to insufficient authorization enforcement for requests to delete scheduled meeting templates. An attacker cou
nvd
CVE-2021-1310P4MEDIUMCVSS 4.7vn/a2021-01-13
CVE-2021-1310 [MEDIUM] CWE-601 CVE-2021-1310: A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthe A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page, bypassing the warning mechanism that should prompt the user before the redirection. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. A
nvd
CVE-2023-20180P4MEDIUMCVSS 4.3v39.10v39.11+30 more2023-07-07
CVE-2023-20180 [MEDIUM] CWE-352 CVE-2023-20180: A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web interface on an affected system. An attacker could exploit this vulnerability by persuading a u
nvd
Cisco Webex Meetings vulnerabilities | cvebase