CVE-2025-66823: TrueConf Server

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).

Affected products

  • TrueConf TrueConf Server: version 5.5.2.10813 only

Published 2025-12-30. Last modified 2026-08-20.