Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Trueconf

First CVE: Jun 29, 2022Active for: 4 yearsTotal CVEs: 15
49.9
VTI Score
TOP TARGET

Trueconf develops a focused video conferencing and unified communications platform centered on its server product, which sits in a prominent niche of on-premises and cloud-hosted collaboration infrastructure. The vendor's vulnerability exposure recurs through web application weakness classes—principally cross-site scripting, SQL injection, cross-site request forgery, and code-integrity issues—that are characteristic of complex web-facing communication systems, with a moderate tendency toward serious severity outcomes and confirmed in-the-wild exploitation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
6.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Trueconf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2022
4 years ago
Most Recent CVE
Mar 30, 2026
116 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-3502HIGH
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tam
Mar 30, 20267.875YESNO
CVE-2022-46764CRITICAL
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately lea
Dec 27, 20229.831NONO
CVE-2025-66824HIGH
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected pay
Dec 30, 20258.727NONO
CVE-2022-46763HIGH
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as
Dec 27, 20228.827NONO
CVE-2017-20120HIGH
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cr
Jun 29, 20228.827NONO
CVE-2025-66835HIGH
TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context.
Dec 30, 20257.126NONO
CVE-2025-66834HIGH
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name
Dec 30, 20257.324NONO
CVE-2017-20119MEDIUM
A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argu
Jun 29, 20226.122NONO
CVE-2017-20118MEDIUM
A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The
Jun 29, 20225.421NONO
CVE-2017-20116MEDIUM
A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the a
Jun 29, 20225.421NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
53%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network13 (86.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (20.0%)
Unknown0 (0.0%)
Required12 (80.0%)
Privileges Required
Low11 (73.3%)
High1 (6.7%)
None3 (20.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
1 CVE
6.7% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Trueconf.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Trueconf — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Trueconf's Products

View all 3 CNAs →

Top CWEs