CRITICAL10.0CVE-2017-7664Apache OpenMeetings does not correctly validate uploaded XML documents >= 3.1.0, < 3.3.0
CRITICAL9.8CVE-2023-28326Apache OpenMeetings missing authentication and can allow user impersonation >= 2.0.0, < 7.0.0
from 0, < 3.1.2
CRITICAL9.8Apache OpenMeetings has Inadequate Encryption Strength
>= 1.0.0, < 3.3.0
HIGH8.8Apache OpenMeetings vulnerable to SQL injection
>= 1.0.0, < 3.3.0
HIGH8.8Apache OpenMeetings vulnerable to Cross-Site Request Forgery
>= 1.0.0, < 3.3.0
HIGH8.2Apache OpenMeetings vulnerable to parameter manipulation attacks
>= 3.2.0, < 3.3.0
HIGH8.1Apache OpenMeetings Improper Authentication vulnerability
>= 3.1.3, < 7.1.0
HIGH7.5Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
>= 3.1.3, < 9.0.0
HIGH7.5Apache OpenMeetings Uses Hard-coded Cryptographic Key
>= 6.1.0, < 9.0.0
HIGH7.5Apache OpenMeetings displays Tomcat version and detailed error stack trace
>= 1.0.0, < 3.3.0
HIGH7.5Apache OpenMeetings allows remote attackers to read arbitrary files by attempting to upload a file
from 0, < 3.1.1
HIGH7.5Apache OpenMeetings vulnerable to Uncontrolled Resource Consumption
>= 1.0.0, < 3.3.0
HIGH7.5Apache OpenMeetings updates user password in insecure manner
>= 1.0.0, < 3.3.0
HIGH7.5Apache OpenMeetings allows flash content to be loaded from untrusted domains
>= 1.0.0, < 3.3.0
HIGH7.5Denial of service in Apache OpenMeetings
>= 4.0.0, < 5.1.0
HIGH7.5Uncontrolled Resource Consumption in Apache OpenMeetings server
>= 4.0.0, < 6.0.0
HIGH7.2Apache OpenMeetings vulnerable to remote code execution via null-bye injection
>= 2.0.0, < 7.1.0
MEDIUM6.5Apache OpenMeetings may allow authenticated attacker to deny service for privileged users
>= 3.0.0, < 4.0.2
MEDIUM6.1Apache OpenMeetings Cross-site Scripting vulnerability
>= 3.2.0, < 3.3.0
MEDIUM6.1Apache OpenMeetings Cross-site Scripting vulnerability
from 0, < 3.1.1
MEDIUM6.1Apache OpenMeetings Cross-site Scripting vulnerability
from 0, < 3.1.2
MEDIUM5.3Apache OpenMeetings responds to insecure HTTP methods
>= 1.0.0, < 3.3.0
MEDIUM4.3Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
>= 3.10, < 9.0.0
—Apache OpenMeetings vulnerable to Deserialization of Untrusted Data
>= 2.1.0, < 8.0.0