8x8 is a unified communications vendor whose vulnerability profile centers on Jitsi Meet, an open-source video-conferencing platform widely deployed for real-time collaboration. The observed weakness classes cluster around web-application input handling and authentication, including cross-site scripting, improper authentication logic, prototype pollution, and default permission misconfigurations that are typical of browser-facing communication software. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 8x8 over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-44081CRITICAL In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message fr | Oct 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2021-39215HIGH Jitsi Meet is an open source video conferencing application. In versions prior to 2.0.5963, a Prosody module allows the use of symmetrical algorithms to validate JSON web tokens. T | Sep 15, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-33506HIGH jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circumvent conference moderation. | May 26, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-44080HIGH In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a mes | Oct 29, 2024 | 7.5 | 21 | NO | NO |
CVE-2021-39205MEDIUM Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON object | Sep 15, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 8x8.
Media articles that mention a CVE ID that affects a product developed by 8x8 — matched by CVE ID, not by vendor name.