VulnSea

trueconf has 4 CVEs on record between 2022 and 2025. The busiest recent month was December 2025 with 3. The median CVSS is 6.3 (medium).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
Last 90 days
0 prev 0

Products

  • trueconf_server 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

trueconf vulnerabilities

CVEs affecting trueconf, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2025-66823Medium· 5.4
8mo ago

An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality

An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim ope…

Sunlittrueconf · trueconf_serverEPSS 0.19%via NVD
CVE-2025-66834High· 7.3
8mo ago

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

Twilighttrueconf · trueconf_serverEPSS 0.30%via NVD
CVE-2025-66824High· 8.7
8mo ago

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and execute…

Twilighttrueconf · trueconf_serverEPSS 0.30%via NVD
CVE-2017-20120Medium· 4.3
4y ago

A vulnerability classified as problematic was found in TrueConf Server 4.3.7

A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated rem…

Sunlittrueconf · trueconf_serverEPSS 0.49%via NVD
trueconf vulnerabilities (CVEs) · VulnSea