CVE-2021-39205
6.8 MEDIUMJitsi Meet is an open source video conferencing application
Published: 2021-09-15 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 6.8 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- CWE
- CWE-1321, CWE-79
Affected products
| Vendor | Product |
|---|---|
| 8x8 | jitsi_meet |
Description
Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild. This issue is fixed in Jitsi Meet version 2.0.6173. There are no known workarounds aside from upgrading.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-39205
- [Patch]https://github.com/jitsi/jitsi-meet/pull/9320
- [Patch]https://github.com/jitsi/jitsi-meet/pull/9404
- [Other]https://github.com/jitsi/jitsi-meet/security/advisories/GHSA-6582-8v9q-v3fg
- [Other]https://hackerone.com/reports/1214493
- [Patch]https://github.com/jitsi/jitsi-meet/pull/9320
- [Patch]https://github.com/jitsi/jitsi-meet/pull/9404
- [Other]https://github.com/jitsi/jitsi-meet/security/advisories/GHSA-6582-8v9q-v3fg
- [Other]https://hackerone.com/reports/1214493
Related CVEs
Same vendor
- CVE-2021-39215 — Jitsi Meet is an open source video conferencing application (7.5 HIGH)
Same CWE
- CVE-2026-12425 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access ...
- CVE-2024-30476 — PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager (5.4 MEDIUM)
- CVE-2026-54198 — Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions (7.1 HIGH)
- CVE-2026-54191 — Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions (7.1 HIGH)
- CVE-2026-39437 — Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions (7.1 HIGH)