Known Vulnerabilities for Openmeetings by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Openmeetings" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34020 json | Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HT... | Not Provided | 2026-04-09 | 2026-04-10 |
| CVE-2026-33266 json | Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to de... | Not Provided | 2026-04-09 | 2026-04-10 |
| CVE-2026-33005 json | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service... | Not Provided | 2026-04-09 | 2026-04-10 |
| CVE-2023-29246 json | An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Fo... | 7.2 - HIGH | 2023-05-12 | 2023-05-22 |
| CVE-2023-29032 json | An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Soft... | 8.1 - HIGH | 2023-05-12 | 2023-05-22 |
| CVE-2023-28936 json | Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings... | 5.3 - MEDIUM | 2023-05-12 | 2023-05-22 |
| CVE-2023-28326 json | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker c... | 9.8 - CRITICAL | 2023-03-28 | 2023-11-07 |
| CVE-2021-27576 json | If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This issue w... | 7.5 - HIGH | 2021-03-15 | 2021-03-22 |
| CVE-2020-13951 json | Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | 7.5 - HIGH | 2020-09-30 | 2023-11-07 |
| CVE-2018-1286 json | In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticate... | 6.5 - MEDIUM | 2018-02-28 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Openmeetings | 6.0.0 | |||
| Application | Apache | Openmeetings | 5.0.1 | |||
| Application | Apache | Openmeetings | 5.0.0 | |||
| Application | Apache | Openmeetings | 4.0.9 | |||
| Application | Apache | Openmeetings | 4.0.3 | |||
| Application | Apache | Openmeetings | 4.0.2 | |||
| Application | Apache | Openmeetings | 4.0.11 | |||
| Application | Apache | Openmeetings | 4.0.10 | |||
| Application | Apache | Openmeetings | 4.0.1 | |||
| Application | Apache | Openmeetings | 4.0.0 | |||
| Application | Apache | Openmeetings | 3.3.2 | |||
| Application | Apache | Openmeetings | 3.3.1 | |||
| Application | Apache | Openmeetings | 3.3.0 | |||
| Application | Apache | Openmeetings | 3.2.1 | |||
| Application | Apache | Openmeetings | 3.2.0 | |||
| Application | Apache | Openmeetings | 3.1.5 | |||
| Application | Apache | Openmeetings | 3.1.4 | |||
| Application | Apache | Openmeetings | 3.1.3 | |||
| Application | Apache | Openmeetings | 3.1.2 | |||
| Application | Apache | Openmeetings | 3.1.1 |