CVE-2023-28599: Zoom

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.

Affected products

  • Zoom Zoom: before 5.13.10 (fixed in 5.13.10)

Published 2023-06-13. Last modified 2026-06-17.