CVE-2025-66834: TrueConf Server

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

Affected products

  • TrueConf TrueConf Server: version 5.5.2.10813 only

Published 2025-12-30. Last modified 2026-08-20.