These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
BigBlueButton is an open-source virtual classroom. A vulnerability in BigBlueButton versions prior to 3.0.29 allows a low-privileged user to store a crafted meeting name that embedded script content. When another user replays the recording, the script executes in their browser. The issue is fixed in version 3.0.29. Users should review and update their installations to prevent potential script execution vi [truncated]
BigBlueButton is an open-source virtual classroom. A vulnerability in BigBlueButton allowed presenters to submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. The akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/RemovePresentationPubMsgHdlr.scala file did not verify the presentation's meeting identifier before deletion, allowing [truncated]
Authenticated moderators in BigBlueButton versions before 3.0.23 could inject SQL via meetingId and userId in refreshBreakoutRoomsVisibleForUsers. The issue is fixed in version 3.0.23. This SQL injection vulnerability allows authenticated moderators to execute arbitrary SQL queries against the application database, potentially leading to data breaches or system compromise. BigBlueButton users and administ [truncated]
CVE-2026-46404 is a vulnerability in BigBlueButton, an open-source virtual classroom. Prior to version 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The issue has been fixed in version 3.0.23. This vulnerability could allow unauthorized access to presentation content. Users of BigBlueButton should review their deployment and update to the [truncated]
CVE-2026-46353 is a security vulnerability in BigBlueButton, an open-source virtual classroom. The issue allows users to bypass checksum validation when a presentationUploadExternalUrl parameter is supplied to API request handling. This problem was addressed in version 3.0.21. Affected product deployments should be identified and patched to prevent potential security bypass. The vulnerability has a high C [truncated]
CVE-2026-46351: BigBlueButton Insufficiently Secure Randomness. The CVE record was published on 2026-07-16T19:16:45.863Z and has not been modified since then. This vulnerability affects BigBlueButton, an open-source virtual classroom, and allows a session user to predict other users' conference session tokens and impersonate them due to insufficiently secure randomness in session token generation. The iss [truncated]
A stored cross-site scripting (XSS) vulnerability exists in BigBlueButton's recording playback feature (presentation format) prior to version 3.0.19. The public chat messages displayed during recording playback were not properly sanitized, allowing a malicious actor to inject and execute arbitrary JavaScript when any user replays an affected recording. The vulnerability requires low privileges to exploit [truncated]