Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:trueconf:server:5.5.2.10813:*:*:*:*:*:*:* |
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trueconf
Trueconf server |
|
| Vendors & Products |
Trueconf
Trueconf server |
Fri, 02 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 30 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-02T14:40:23.211Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-66823
Updated: 2026-01-02T14:38:01.384Z
Status : Analyzed
Published: 2025-12-30T20:16:01.413
Modified: 2026-01-07T15:39:03.947
Link: CVE-2025-66823
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:22:14Z