cbcvebase.

Trueconf Server vulnerabilities

8 known vulnerabilities affecting trueconf/trueconf_server.

Total CVEs
8
CISA KEV
2
actively exploited
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-72529P1CRITICALCVSS 9.8KEVfixed in 5.3.9.10013fixed in 5.3.9.10015+8 more2026-08-19
CVE-2026-72529 [CRITICAL] CWE-306 CVE-2026-72529: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
nvd
CVE-2026-72530P1CRITICALCVSS 9.0KEVfixed in 5.3.9.10013fixed in 5.3.9.10015+8 more2026-08-19
CVE-2026-72530 [CRITICAL] CWE-94 CVE-2026-72530: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
nvd
CVE-2022-46764P2CRITICALCVSS 9.8v5.2.0.102252022-12-27
CVE-2022-46764 [CRITICAL] CWE-89 CVE-2022-46764: A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows re A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.
nvd
CVE-2022-46763P3HIGHCVSS 8.8v5.2.0.102252022-12-27
CVE-2022-46763 [HIGH] CWE-89 CVE-2022-46763: A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.1 A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.
nvd
CVE-2025-66824P3HIGHCVSS 8.7v5.5.2.108132025-12-30
CVE-2025-66824 [HIGH] CWE-79 CVE-2025-66824: A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is
nvd
CVE-2017-20120P3HIGHCVSS 8.8v4.3.7.12219v4.3.7.122552022-06-29
CVE-2017-20120 [HIGH] CWE-352 CVE-2017-20120: A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability aff A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-66834P3HIGHCVSS 7.3v5.5.2.108132025-12-30
CVE-2025-66834 [HIGH] CWE-1236 CVE-2025-66834: A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
nvd
CVE-2025-66823P4MEDIUMCVSS 5.4v5.5.2.108132025-12-30
CVE-2025-66823 [MEDIUM] CWE-79 CVE-2025-66823: An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field a An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).
nvd
Trueconf Server vulnerabilities | cvebase