{"schema_version":1,"title":"org.apache.openmeetings:openmeetings-parent (Maven) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 25 vulnerabilities in org.apache.openmeetings:openmeetings-parent (Maven): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-34020, was published on 9 April 2026.","url":"https://junglewise.ai/threats/technologies/org-apache-openmeetings-openmeetings-parent","json_url":"https://junglewise.ai/threats/technologies/org-apache-openmeetings-openmeetings-parent.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/org-apache-openmeetings-openmeetings-parent","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":25,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":3},"latest":[{"cve":"CVE-2026-34020","cvss":7.5,"epss":0.0079,"slug":"cve-2026-34020-apache-openmeetings-information-exposure-in-rest-login-endpoint","title":"Apache OpenMeetings information exposure in REST login endpoint","severity":"high","exploited":false,"published_at":"2026-04-09T18:31:27+00:00","url":"https://junglewise.ai/threats/cve-2026-34020-apache-openmeetings-information-exposure-in-rest-login-endpoint"},{"cve":"CVE-2026-33005","cvss":4.3,"epss":0.0065,"slug":"cve-2026-33005-apache-openmeetings-insufficient-privilege-checks-in","title":"Apache OpenMeetings insufficient privilege checks in FileWebService","severity":"medium","exploited":false,"published_at":"2026-04-09T18:31:26+00:00","url":"https://junglewise.ai/threats/cve-2026-33005-apache-openmeetings-insufficient-privilege-checks-in"},{"cve":"CVE-2026-33266","cvss":7.5,"epss":0.0035,"slug":"cve-2026-33266-apache-openmeetings-hard-coded-cryptographic-key-in-remember-me","title":"Apache OpenMeetings hard-coded cryptographic key in remember-me cookies","severity":"high","exploited":false,"published_at":"2026-04-09T18:31:26+00:00","url":"https://junglewise.ai/threats/cve-2026-33266-apache-openmeetings-hard-coded-cryptographic-key-in-remember-me"},{"cve":"CVE-2024-54676","cvss":4,"epss":0.6494,"slug":"cve-2024-54676-apache-openmeetings-vulnerable-to-deserialization-of-untrusted","title":"Apache OpenMeetings vulnerable to Deserialization of Untrusted Data","severity":"medium","exploited":false,"published_at":"2025-01-08T09:30:39+00:00","url":"https://junglewise.ai/threats/cve-2024-54676-apache-openmeetings-vulnerable-to-deserialization-of-untrusted"},{"cve":"CVE-2023-29032","cvss":3.1,"epss":0.0109,"slug":"cve-2023-29032-apache-openmeetings-improper-authentication-vulnerability","title":"Apache OpenMeetings Improper Authentication vulnerability","severity":"low","exploited":false,"published_at":"2023-05-12T09:30:15+00:00","url":"https://junglewise.ai/threats/cve-2023-29032-apache-openmeetings-improper-authentication-vulnerability"},{"cve":"CVE-2023-29246","cvss":3.1,"epss":0.0146,"slug":"cve-2023-29246-apache-openmeetings-vulnerable-to-remote-code-execution-via-null","title":"Apache OpenMeetings vulnerable to remote code execution via null-bye injection","severity":"low","exploited":false,"published_at":"2023-05-12T09:30:14+00:00","url":"https://junglewise.ai/threats/cve-2023-29246-apache-openmeetings-vulnerable-to-remote-code-execution-via-null"},{"cve":"CVE-2023-28326","cvss":3.1,"epss":0.0126,"slug":"cve-2023-28326-apache-openmeetings-missing-authentication-and-can-allow-user","title":"Apache OpenMeetings missing authentication and can allow user impersonation","severity":"low","exploited":false,"published_at":"2023-03-28T15:30:18+00:00","url":"https://junglewise.ai/threats/cve-2023-28326-apache-openmeetings-missing-authentication-and-can-allow-user"},{"cve":"CVE-2017-7681","cvss":3,"epss":0.0129,"slug":"cve-2017-7681-apache-openmeetings-vulnerable-to-sql-injection","title":"Apache OpenMeetings vulnerable to SQL injection","severity":"low","exploited":false,"published_at":"2022-05-17T02:28:11+00:00","url":"https://junglewise.ai/threats/cve-2017-7681-apache-openmeetings-vulnerable-to-sql-injection"},{"cve":"CVE-2017-7663","cvss":3,"epss":0.0267,"slug":"cve-2017-7663-apache-openmeetings-cross-site-scripting-vulnerability","title":"Apache OpenMeetings Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2022-05-17T02:28:11+00:00","url":"https://junglewise.ai/threats/cve-2017-7663-apache-openmeetings-cross-site-scripting-vulnerability"},{"cve":"CVE-2017-7666","cvss":3,"epss":0.008,"slug":"cve-2017-7666-apache-openmeetings-vulnerable-to-cross-site-request-forgery","title":"Apache OpenMeetings vulnerable to Cross-Site Request Forgery","severity":"low","exploited":false,"published_at":"2022-05-17T02:28:11+00:00","url":"https://junglewise.ai/threats/cve-2017-7666-apache-openmeetings-vulnerable-to-cross-site-request-forgery"},{"cve":"CVE-2017-7683","cvss":3,"epss":0.02,"slug":"cve-2017-7683-apache-openmeetings-displays-tomcat-version-and-detailed-error","title":"Apache OpenMeetings displays Tomcat version and detailed error stack trace","severity":"low","exploited":false,"published_at":"2022-05-17T02:28:11+00:00","url":"https://junglewise.ai/threats/cve-2017-7683-apache-openmeetings-displays-tomcat-version-and-detailed-error"},{"cve":"CVE-2017-7664","cvss":3,"epss":0.0235,"slug":"cve-2017-7664-apache-openmeetings-does-not-correctly-validate-uploaded-xml","title":"Apache OpenMeetings does not correctly validate uploaded XML documents","severity":"low","exploited":false,"published_at":"2022-05-17T02:28:11+00:00","url":"https://junglewise.ai/threats/cve-2017-7664-apache-openmeetings-does-not-correctly-validate-uploaded-xml"},{"cve":"CVE-2016-2163","cvss":3,"epss":0.0797,"slug":"cve-2016-2163-apache-openmeetings-cross-site-scripting-vulnerability","title":"Apache OpenMeetings Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T02:46:39+00:00","url":"https://junglewise.ai/threats/cve-2016-2163-apache-openmeetings-cross-site-scripting-vulnerability"},{"cve":"CVE-2016-2164","cvss":3,"epss":0.0701,"slug":"cve-2016-2164-apache-openmeetings-allows-remote-attackers-to-read-arbitrary","title":"Apache OpenMeetings allows remote attackers to read arbitrary files by attempting to upload a file","severity":"low","exploited":false,"published_at":"2022-05-14T02:46:39+00:00","url":"https://junglewise.ai/threats/cve-2016-2164-apache-openmeetings-allows-remote-attackers-to-read-arbitrary"},{"cve":"CVE-2016-3089","cvss":3,"epss":0.0486,"slug":"cve-2016-3089-apache-openmeetings-cross-site-scripting-vulnerability","title":"Apache OpenMeetings Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T02:46:33+00:00","url":"https://junglewise.ai/threats/cve-2016-3089-apache-openmeetings-cross-site-scripting-vulnerability"},{"cve":"CVE-2016-8736","cvss":3,"epss":0.0478,"slug":"cve-2016-8736-apache-openmeetings-rce","title":"Apache OpenMeetings RCE","severity":"low","exploited":false,"published_at":"2022-05-14T01:29:42+00:00","url":"https://junglewise.ai/threats/cve-2016-8736-apache-openmeetings-rce"},{"cve":"CVE-2018-1286","cvss":3,"epss":0.0109,"slug":"cve-2018-1286-apache-openmeetings-may-allow-authenticated-attacker-to-deny","title":"Apache OpenMeetings may allow authenticated attacker to deny service for privileged users","severity":"low","exploited":false,"published_at":"2022-05-13T01:49:39+00:00","url":"https://junglewise.ai/threats/cve-2018-1286-apache-openmeetings-may-allow-authenticated-attacker-to-deny"},{"cve":"CVE-2017-7684","cvss":3,"epss":0.0281,"slug":"cve-2017-7684-apache-openmeetings-vulnerable-to-uncontrolled-resource","title":"Apache OpenMeetings vulnerable to Uncontrolled Resource Consumption","severity":"low","exploited":false,"published_at":"2022-05-13T01:47:06+00:00","url":"https://junglewise.ai/threats/cve-2017-7684-apache-openmeetings-vulnerable-to-uncontrolled-resource"},{"cve":"CVE-2017-7685","cvss":3,"epss":0.0286,"slug":"cve-2017-7685-apache-openmeetings-responds-to-insecure-http-methods","title":"Apache OpenMeetings responds to insecure HTTP methods","severity":"low","exploited":false,"published_at":"2022-05-13T01:47:05+00:00","url":"https://junglewise.ai/threats/cve-2017-7685-apache-openmeetings-responds-to-insecure-http-methods"},{"cve":"CVE-2017-7688","cvss":3,"epss":0.0297,"slug":"cve-2017-7688-apache-openmeetings-updates-user-password-in-insecure-manner","title":"Apache OpenMeetings updates user password in insecure manner","severity":"low","exploited":false,"published_at":"2022-05-13T01:47:05+00:00","url":"https://junglewise.ai/threats/cve-2017-7688-apache-openmeetings-updates-user-password-in-insecure-manner"},{"cve":"CVE-2017-7682","cvss":3,"epss":0.0164,"slug":"cve-2017-7682-apache-openmeetings-vulnerable-to-parameter-manipulation-attacks","title":"Apache OpenMeetings vulnerable to parameter manipulation attacks","severity":"low","exploited":false,"published_at":"2022-05-13T01:47:04+00:00","url":"https://junglewise.ai/threats/cve-2017-7682-apache-openmeetings-vulnerable-to-parameter-manipulation-attacks"},{"cve":"CVE-2017-7673","cvss":3,"epss":0.0165,"slug":"cve-2017-7673-apache-openmeetings-has-inadequate-encryption-strength","title":"Apache OpenMeetings has Inadequate Encryption Strength","severity":"low","exploited":false,"published_at":"2022-05-13T01:47:04+00:00","url":"https://junglewise.ai/threats/cve-2017-7673-apache-openmeetings-has-inadequate-encryption-strength"},{"cve":"CVE-2017-7680","cvss":3,"epss":0.0181,"slug":"cve-2017-7680-apache-openmeetings-allows-flash-content-to-be-loaded-from","title":"Apache OpenMeetings allows flash content to be loaded from untrusted domains","severity":"low","exploited":false,"published_at":"2022-05-13T01:47:04+00:00","url":"https://junglewise.ai/threats/cve-2017-7680-apache-openmeetings-allows-flash-content-to-be-loaded-from"},{"cve":"CVE-2020-13951","cvss":3.1,"epss":0.6858,"slug":"cve-2020-13951-denial-of-service-in-apache-openmeetings","title":"Denial of service in Apache OpenMeetings","severity":"low","exploited":false,"published_at":"2022-02-10T20:36:45+00:00","url":"https://junglewise.ai/threats/cve-2020-13951-denial-of-service-in-apache-openmeetings"},{"cve":"CVE-2021-27576","cvss":3.1,"epss":0.0284,"slug":"cve-2021-27576-uncontrolled-resource-consumption-in-apache-openmeetings-server","title":"Uncontrolled Resource Consumption in Apache OpenMeetings server","severity":"low","exploited":false,"published_at":"2021-06-16T17:43:36+00:00","url":"https://junglewise.ai/threats/cve-2021-27576-uncontrolled-resource-consumption-in-apache-openmeetings-server"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"com.liferay.portal:release.portal.bom (Maven)","slug":"com-liferay-portal-release-portal-bom","vulnerabilities":92,"url":"https://junglewise.ai/threats/technologies/com-liferay-portal-release-portal-bom"},{"name":"org.keycloak:keycloak-services (Maven)","slug":"org-keycloak-keycloak-services","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-services"},{"name":"org.keycloak:keycloak-core (Maven)","slug":"org-keycloak-keycloak-core","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-core"},{"name":"org.apache.struts:struts2-core (Maven)","slug":"org-apache-struts-struts2-core","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/org-apache-struts-struts2-core"},{"name":"net.mingsoft:ms-mcms (Maven)","slug":"net-mingsoft-ms-mcms","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/net-mingsoft-ms-mcms"},{"name":"com.thoughtworks.xstream:xstream (Maven)","slug":"com-thoughtworks-xstream-xstream","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream"},{"name":"com.jfinal:jfinal (Maven)","slug":"com-jfinal-jfinal","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/com-jfinal-jfinal"},{"name":"org.jenkins-ci.plugins:script-security (Maven)","slug":"org-jenkins-ci-plugins-script-security","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-script-security"},{"name":"org.apache.tomcat:tomcat (Maven)","slug":"org-apache-tomcat-tomcat","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/org-apache-tomcat-tomcat"},{"name":"com.liferay.portal:release.dxp.bom (Maven)","slug":"com-liferay-portal-release-dxp-bom","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/com-liferay-portal-release-dxp-bom"},{"name":"org.opencms:opencms-core (Maven)","slug":"org-opencms-opencms-core","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/org-opencms-opencms-core"},{"name":"org.keycloak:keycloak-parent (Maven)","slug":"org-keycloak-keycloak-parent","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-parent"}],"technology":{"hub":true,"name":"org.apache.openmeetings:openmeetings-parent (Maven)","slug":"org-apache-openmeetings-openmeetings-parent","vendor":{"name":"Maven","slug":"maven","url":"https://junglewise.ai/threats/vendors/maven"},"aliases":[],"homepage":"https://openmeetings.apache.org/","repo_url":"https://github.com/apache/openmeetings","description":"The parent project for Apache OpenMeetings, a web-based conferencing application.","url":"https://junglewise.ai/threats/technologies/org-apache-openmeetings-openmeetings-parent"},"most_severe":[{"cve":"CVE-2026-34020","cvss":7.5,"epss":0.0079,"slug":"cve-2026-34020-apache-openmeetings-information-exposure-in-rest-login-endpoint","title":"Apache OpenMeetings information exposure in REST login endpoint","severity":"high","exploited":false,"published_at":"2026-04-09T18:31:27+00:00","url":"https://junglewise.ai/threats/cve-2026-34020-apache-openmeetings-information-exposure-in-rest-login-endpoint"},{"cve":"CVE-2026-33266","cvss":7.5,"epss":0.0035,"slug":"cve-2026-33266-apache-openmeetings-hard-coded-cryptographic-key-in-remember-me","title":"Apache OpenMeetings hard-coded cryptographic key in remember-me cookies","severity":"high","exploited":false,"published_at":"2026-04-09T18:31:26+00:00","url":"https://junglewise.ai/threats/cve-2026-33266-apache-openmeetings-hard-coded-cryptographic-key-in-remember-me"},{"cve":"CVE-2026-33005","cvss":4.3,"epss":0.0065,"slug":"cve-2026-33005-apache-openmeetings-insufficient-privilege-checks-in","title":"Apache OpenMeetings insufficient privilege checks in FileWebService","severity":"medium","exploited":false,"published_at":"2026-04-09T18:31:26+00:00","url":"https://junglewise.ai/threats/cve-2026-33005-apache-openmeetings-insufficient-privilege-checks-in"},{"cve":"CVE-2024-54676","cvss":4,"epss":0.6494,"slug":"cve-2024-54676-apache-openmeetings-vulnerable-to-deserialization-of-untrusted","title":"Apache OpenMeetings vulnerable to Deserialization of Untrusted Data","severity":"medium","exploited":false,"published_at":"2025-01-08T09:30:39+00:00","url":"https://junglewise.ai/threats/cve-2024-54676-apache-openmeetings-vulnerable-to-deserialization-of-untrusted"},{"cve":"CVE-2020-13951","cvss":3.1,"epss":0.6858,"slug":"cve-2020-13951-denial-of-service-in-apache-openmeetings","title":"Denial of service in Apache OpenMeetings","severity":"low","exploited":false,"published_at":"2022-02-10T20:36:45+00:00","url":"https://junglewise.ai/threats/cve-2020-13951-denial-of-service-in-apache-openmeetings"},{"cve":"CVE-2021-27576","cvss":3.1,"epss":0.0284,"slug":"cve-2021-27576-uncontrolled-resource-consumption-in-apache-openmeetings-server","title":"Uncontrolled Resource Consumption in Apache OpenMeetings server","severity":"low","exploited":false,"published_at":"2021-06-16T17:43:36+00:00","url":"https://junglewise.ai/threats/cve-2021-27576-uncontrolled-resource-consumption-in-apache-openmeetings-server"},{"cve":"CVE-2023-29246","cvss":3.1,"epss":0.0146,"slug":"cve-2023-29246-apache-openmeetings-vulnerable-to-remote-code-execution-via-null","title":"Apache OpenMeetings vulnerable to remote code execution via null-bye injection","severity":"low","exploited":false,"published_at":"2023-05-12T09:30:14+00:00","url":"https://junglewise.ai/threats/cve-2023-29246-apache-openmeetings-vulnerable-to-remote-code-execution-via-null"},{"cve":"CVE-2023-28326","cvss":3.1,"epss":0.0126,"slug":"cve-2023-28326-apache-openmeetings-missing-authentication-and-can-allow-user","title":"Apache OpenMeetings missing authentication and can allow user impersonation","severity":"low","exploited":false,"published_at":"2023-03-28T15:30:18+00:00","url":"https://junglewise.ai/threats/cve-2023-28326-apache-openmeetings-missing-authentication-and-can-allow-user"},{"cve":"CVE-2023-29032","cvss":3.1,"epss":0.0109,"slug":"cve-2023-29032-apache-openmeetings-improper-authentication-vulnerability","title":"Apache OpenMeetings Improper Authentication vulnerability","severity":"low","exploited":false,"published_at":"2023-05-12T09:30:15+00:00","url":"https://junglewise.ai/threats/cve-2023-29032-apache-openmeetings-improper-authentication-vulnerability"},{"cve":"CVE-2016-2163","cvss":3,"epss":0.0797,"slug":"cve-2016-2163-apache-openmeetings-cross-site-scripting-vulnerability","title":"Apache OpenMeetings Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2022-05-14T02:46:39+00:00","url":"https://junglewise.ai/threats/cve-2016-2163-apache-openmeetings-cross-site-scripting-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}