Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-12246
A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/…
Chatwoot
after 4.7.0
MEDIUM 5.3
CVE-2025-12245
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascri…
Chatwoot
after 4.7.0
HIGH 8.8
CVE-2025-21628
Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator pas…
Chatwoot
3.16.0+
HIGH 8.8
CVE-2021-3742
A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allo…
Chatwoot
2.5.0+
MEDIUM 5.4
CVE-2021-3741
A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs …
Chatwoot
2.6.0+
MEDIUM 6.8
CVE-2021-3740
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other …
Chatwoot
2.4.0+
MEDIUM 6.1
CVE-2023-2109
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.
Chatwoot
2.14.0+
CRITICAL 9.8
CVE-2022-3741
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system…
Chatwoot
2.10.0+
HIGH 7.1
CVE-2022-2901
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
Chatwoot
2.8.0+
MEDIUM 6.1
CVE-2022-0542
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.
Chatwoot
2.7.0+
MEDIUM 5.4
CVE-2022-1021
Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.
Chatwoot
2.6.0+
MEDIUM 5.4
CVE-2022-1022
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
Chatwoot
2.5.0+
MEDIUM 6.5
CVE-2021-3813
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
Chatwoot
after 2.1.1
MEDIUM 6.1
CVE-2022-0526
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
Chatwoot
after 2.1.1
MEDIUM 6.1
CVE-2022-0527
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
Chatwoot
after 2.1.1
HIGH 7.5
CVE-2021-3649
chatwoot is vulnerable to Inefficient Regular Expression Complexity
Chatwoot
1.18.0+