CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trueconf 1Trueconf Server Aug 21, 2026 Aug 19, 2026 9.5 CRITICAL· v4 9.0 CRITICAL· v3 N/A· v2 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the is...Show more |
1Trueconf 1Trueconf Server Aug 21, 2026 Aug 19, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumente...Show more |
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered wh...Show more |
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name. |
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room para...Show more |
1Trueconf 2Server Trueconf ServerAug 20, 2026 Jun 29, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can...Show more |