Skip to main content

Vendor/product archive

apache / openmeetings CVEs

Beta · best-effort

29 CVEs tagged to apache / openmeetings5 Critical, 15 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2026-49488

Published Jul 14, 2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34020

Published Apr 9, 2026

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as que…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-33266

Published Apr 9, 2026

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being a…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-33005

Published Apr 9, 2026

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of a…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-54676

Published Jan 8, 2025

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apach…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-29246

Published May 12, 2023

An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-29032

Published May 12, 2023

An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeeting…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28936

Published May 12, 2023

Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-28326

Published Mar 28, 2023

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27576

Published Mar 15, 2021

If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue was addressed in Apache OpenMeetings 6.0.0

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13951

Published Sep 30, 2020

Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1286

Published Feb 28, 2018

In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8736

Published Oct 12, 2017

Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7688

Published Jul 17, 2017

Apache OpenMeetings 1.0.0 updates user password in insecure manner.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7685

Published Jul 17, 2017

Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7684

Published Jul 17, 2017

Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files to the server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7683

Published Jul 17, 2017

Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7682

Published Jul 17, 2017

Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7681

Published Jul 17, 2017

Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries bei…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7680

Published Jul 17, 2017

Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7673

Published Jul 17, 2017

Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7666

Published Jul 17, 2017

Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7663

Published Jul 17, 2017

Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3089

Published Aug 19, 2016

Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the swf parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2