Hamastar develops MeetingHub, a paperless meetings application, with a durable signal centered on file-handling and authentication weaknesses including unrestricted file uploads, absolute path traversal, insufficiently protected credentials, missing authentication controls, and plaintext password storage. These issues reflect the application's document-management and user-access demands; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hamastar over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1331CRITICAL MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby | Jan 22, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-1330HIGH MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbit | Jan 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-6118CRITICAL A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials | Aug 5, 2024 | 9.1 | 24 | NO | NO |
CVE-2024-6117HIGH A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to p | Aug 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-1332MEDIUM MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meetin | Jan 22, 2026 | 5.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hamastar.
Media articles that mention a CVE ID that affects a product developed by Hamastar — matched by CVE ID, not by vendor name.