Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-72530
Remote Code Execution via Script Upload in TrueConf Server
CVE-2026-72529
TrueConf Server Remote Unauthorized Function Enables Arbitrary Script Execution via Port 4307
CVE-2026-3502
TrueConf Client Update Integrity Verification Bypass
CVE-2025-66824
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.
CVE-2025-66835
TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context.
