Bigbluebutton is a widely adopted open-source web conferencing platform that delivers real-time collaboration and remote learning capabilities across educational institutions and enterprises, making it a prominent fixture in distributed-work infrastructure despite a narrow product portfolio. Its vulnerability footprint clusters around the core Bigbluebutton application and its Greenlight interface layer, where exposures recur through web-application-oriented weakness classes including cross-site scripting, sensitive information disclosure, and authorization flaws that are characteristic of server-side web frameworks handling user input and access control. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitive nature of meeting content and participant data at risk. Defenders should prioritize patching instances in use, particularly for internet-facing deployments and installations serving sensitive communications; current exploitation activity and severity breakdowns are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bigbluebutton over time
Signals from CVEs in this vendor scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25820MEDIUM BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink fie | Oct 21, 2020 | 6.5 | 35 | NO | YES |
CVE-2020-12443CRITICAL BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) val | Apr 29, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-27602CRITICAL BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken. | Sep 29, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-27605CRITICAL BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox." | Oct 21, 2020 | 9.8 | 29 | NO | NO |
CVE-2026-27466HIGH BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file sc | Feb 21, 2026 | 8.2 | 27 | NO | NO |
CVE-2020-26163HIGH BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link. | Sep 30, 2020 | 8.8 | 26 | NO | NO |
CVE-2025-61602HIGH BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality | Oct 9, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-61601HIGH BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire s | Oct 9, 2025 | 7.5 | 25 | NO | NO |
CVE-2020-27613HIGH The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access. | Oct 21, 2020 | 8.4 | 25 | NO | NO |
CVE-2023-42803HIGH BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not | Oct 30, 2023 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (55 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bigbluebutton.
Media articles that mention a CVE ID that affects a product developed by Bigbluebutton — matched by CVE ID, not by vendor name.