Agora's vulnerability footprint centers on its video software development kit, a component embedded in real-time communication applications. The observed weakness is cleartext transmission of sensitive information, reflecting the security surface of a network-facing communications protocol library. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Agora over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67079CRITICAL File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file | Jan 15, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-67077HIGH File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action. | Jan 15, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-67076HIGH Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGet | Jan 15, 2026 | 7.5 | 25 | NO | NO |
CVE-2020-25605MEDIUM Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through | Feb 17, 2021 | 5.9 | 22 | NO | NO |
CVE-2025-67078MEDIUM Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used t | Jan 15, 2026 | 6.1 | 21 | NO | NO |
CVE-2017-6561MEDIUM XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack. | Mar 9, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-6559MEDIUM XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack. | Mar 9, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-6562MEDIUM XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack. | Mar 9, 2017 | 6.1 | 20 | NO | NO |
CVE-2017-6560MEDIUM XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack. | Mar 9, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Agora.
Media articles that mention a CVE ID that affects a product developed by Agora — matched by CVE ID, not by vendor name.