๐Ÿ” CVE Alert

CVE-2026-55491

MEDIUM 5.4

BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Name

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user could store a crafted meeting name that embedded script content, and the script executed in another user's browser when that user replayed the recording. This issue is fixed in version 3.0.29.

CWE CWE-79
Vendor bigbluebutton
Product bigbluebutton
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for bigbluebutton bigbluebutton

Be the first to know when new medium vulnerabilities affecting bigbluebutton bigbluebutton are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

bigbluebutton / bigbluebutton
< 3.0.29

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-57p5-c888-74f9 github.com: https://github.com/bigbluebutton/bigbluebutton/commit/a53f2b92022388bfa4109d3136d1f3a932404b1b github.com: https://github.com/bigbluebutton/bigbluebutton/releases/tag/v3.0.29