Vulnerability index

Browse CVEs

49 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rocket.chat MEDIUM 6.5
CVE-2022-32227

A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "v…

Fix: 4.7.5 / 4.8.2+
Fix from $1,600 2022-09-23
Rocket.chat MEDIUM 5.3
CVE-2022-32217

A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs.

Fix: 4.6.4+
Fix from $1,600 2022-09-23
Livechat MEDIUM 6.1
CVE-2022-21830

A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their cha…

Fix: 1.9.0+
Fix from $1,600 2022-04-01
Rocket.chat MEDIUM 6.1
CVE-2020-8291

A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.

Fix: 3.9.0+
Fix from $1,600 2021-10-18
Rocket.chat MEDIUM 6.5
CVE-2021-32832

Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and …

Fix: 3.11.3 / 3.12.2+
Fix from $1,600 2021-08-30
Rocket.chat CRITICAL 9.8
CVE-2021-22910

A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result i…

Fix: 3.11.4 / 3.12.4+
Fix from $2,300 2021-08-09
Rocket.chat HIGH 7.5
CVE-2020-26763

The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.

Patch available
Fix from $1,950 2021-07-05
Rocket.chat CRITICAL 9.8
CVE-2021-22911EPSS 95%

A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, result…

No fix yet
Fix from $2,300 2021-05-27
Rocket.chat HIGH 7.5
CVE-2021-22892

An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed …

Fix: 3.11.3 / 3.12.2+
Fix from $1,950 2021-05-27
Rocket.chat MEDIUM 6.1
CVE-2021-22886

Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote att…

Fix: 3.8.8 / 3.9.7+
Fix from $1,600 2021-03-26
Rocket.chat MEDIUM 5.4
CVE-2020-8288

The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parame…

Fix: 3.9.2+
Fix from $1,600 2021-01-26
Rocket.chat MEDIUM 5.4
CVE-2020-8292

Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.

Fix: 3.9.0+
Fix from $1,600 2021-01-26
Rocket.chat MEDIUM 5.3
CVE-2020-28208EPSS 11%

An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.

Fix: after 3.9.1
Fix from $1,600 2021-01-08
Rocket.chat CRITICAL 9.8
CVE-2020-29594

Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.

Fix: 0.74.4 / 1.3.4+
Fix from $2,300 2020-12-30
Rocket.chat MEDIUM 6.1
CVE-2020-15926

Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which r…

Fix: after 3.4.2
Fix from $1,600 2020-08-18
Rocket.chat MEDIUM 6.1
CVE-2019-17220

Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.

Fix: 2.1.0+
Fix from $1,600 2019-10-21
Rocket.chat MEDIUM 6.1
CVE-2018-13878

An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescape…

Fix: 0.65+
Fix from $1,600 2018-07-11
Rocket.chat MEDIUM 5.4
CVE-2018-13879

A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a u…

Fix: 0.66+
Fix from $1,600 2018-07-11
Rocket.chat CRITICAL 9.8
CVE-2017-1000493

Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

Fix: after 0.59
Fix from $2,300 2018-01-03