Server
Vendor:
First CVE: Jun 29, 2022 · Active for 4 years
13
Total CVEs
More Total CVEs than 91% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 29, 2022
4 years ago
Most Recent CVE
Dec 30, 2025
206 days ago
CVE Severity & Scoring
Server13 CVEs
62%
31%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (15.4%)
Unknown0 (0.0%)
Required11 (84.6%)
Privileges Required
Low10 (76.9%)
High0 (0.0%)
None3 (23.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46764CRITICAL A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately lea | Dec 27, 2022 | 9.8 | 31 | NO | NO |
CVE-2025-66824HIGH A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected pay | Dec 30, 2025 | 8.7 | 27 | NO | NO |
CVE-2022-46763HIGH A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as | Dec 27, 2022 | 8.8 | 27 | NO | NO |
CVE-2017-20120HIGH A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cr | Jun 29, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-66834HIGH A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name | Dec 30, 2025 | 7.3 | 24 | NO | NO |
CVE-2017-20119MEDIUM A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argu | Jun 29, 2022 | 6.1 | 22 | NO | NO |
CVE-2017-20118MEDIUM A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The | Jun 29, 2022 | 5.4 | 21 | NO | NO |
CVE-2017-20116MEDIUM A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the a | Jun 29, 2022 | 5.4 | 21 | NO | NO |
CVE-2017-20117MEDIUM A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The ma | Jun 29, 2022 | 5.4 | 20 | NO | NO |
CVE-2017-20115MEDIUM A vulnerability was found in TrueConf Server 4.3.7 and classified as problematic. This issue affects some unknown processing of the file /admin/conferences/list/. The manipulation | Jun 29, 2022 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.5.2.10813 | 3 | 7.1 | 0.2% | 0 | 0 |
| 4.3.7.12255 | 1 | 8.8 | 0.5% | 0 | 0 |
| 4.3.7.12219 | 1 | 8.8 | 0.5% | 0 | 0 |