Loading
Generated remediation guidance and an executive summary. No account required.
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.
Cite this page
CVE-2020-27608. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2020-27608
Use CWE-79, Bigbluebutton vendor hub and Bigbluebutton product page to widen CVE-2020-27608 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-61602, CVE-2025-61601 and CVE-2026-27466 for nearby disclosures in the same product family.