Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bigbluebutton

First CVE: Apr 23, 2020Active for: 6 yearsTotal CVEs: 55
34.1
VTI Score
Medium

Bigbluebutton is a widely adopted open-source web conferencing platform that delivers real-time collaboration and remote learning capabilities across educational institutions and enterprises, making it a prominent fixture in distributed-work infrastructure despite a narrow product portfolio. Its vulnerability footprint clusters around the core Bigbluebutton application and its Greenlight interface layer, where exposures recur through web-application-oriented weakness classes including cross-site scripting, sensitive information disclosure, and authorization flaws that are characteristic of server-side web frameworks handling user input and access control. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitive nature of meeting content and participant data at risk. Defenders should prioritize patching instances in use, particularly for internet-facing deployments and installations serving sensitive communications; current exploitation activity and severity breakdowns are shown alongside this summary.

FAUCET AI Generated
55
Total CVEs
More Total CVEs than 99% of tracked vendors
4.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bigbluebutton over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2020
6 years ago
Most Recent CVE
Feb 25, 2026
149 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-25820MEDIUM
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink fie
Oct 21, 20206.535NOYES
CVE-2020-12443CRITICAL
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) val
Apr 29, 20209.831NONO
CVE-2020-27602CRITICAL
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
Sep 29, 20229.830NONO
CVE-2020-27605CRITICAL
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."
Oct 21, 20209.829NONO
CVE-2026-27466HIGH
BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file sc
Feb 21, 20268.227NONO
CVE-2020-26163HIGH
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.
Sep 30, 20208.826NONO
CVE-2025-61602HIGH
BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality
Oct 9, 20257.525NONO
CVE-2025-61601HIGH
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire s
Oct 9, 20257.525NONO
CVE-2020-27613HIGH
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.
Oct 21, 20208.425NONO
CVE-2023-42803HIGH
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not
Oct 30, 20238.824NONO
View all 55 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products55 CVEs
9%
62%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.8%)
Network54 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (96.4%)
High2 (3.6%)
Unknown0 (0.0%)
User Interaction
None38 (69.1%)
Unknown0 (0.0%)
Required17 (30.9%)
Privileges Required
Low21 (38.2%)
High2 (3.6%)
None32 (58.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bigbluebutton.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bigbluebutton — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bigbluebutton's Products

View all 3 CNAs →

Top CWEs