Vulnerability index

Browse CVEs

49 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-48929 Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The del… Rocket.chat 7.10.13 / 7.13.9+ Fix from $1,9502026-06-17 CRITICAL 9.3 CVE-2026-48616 Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file… Rocket.chat 7.10.13 / 7.13.9+ Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-29198 In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover o… Rocket.chat 7.10.9 / 7.11.6+ Fix from $2,3002026-04-23 MEDIUM 5.3 CVE-2026-22560 An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters with… Rocket.chat 8.4.0+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-30833 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, an… Rocket.chat 7.10.8 / 7.11.5+ Fix from $1,6002026-03-06 CRITICAL 9.8 CVE-2026-30831 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, an… Rocket.chat 7.10.8 / 7.11.5+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28514 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, an… Rocket.chat 7.8.6 / 7.9.8+ Fix from $2,3002026-03-06 MEDIUM 6.5 CVE-2026-23477 Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1… Rocket.chat 6.12.0+ Fix from $1,6002026-01-14 HIGH 7.5 CVE-2025-7974 rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio… Rocket.chat 7.4.4 / 7.5.3+ Fix from $1,9502025-09-02 HIGH 7.5 CVE-2025-5892 A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the f… Rocket.chat after 7.6.1 Fix from $1,9502025-06-09 HIGH 7.5 CVE-2024-46935 Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with spec… Rocket.chat 6.7.9 / 6.8.7+ Fix from $1,9502024-09-25 MEDIUM 6.1 CVE-2024-46934 Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to … Rocket.chat 6.7.9 / 6.8.7+ Fix from $1,6002024-09-25 MEDIUM 5.4 CVE-2024-47048 Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and pr… Rocket.chat 6.7.9 / 6.8.7+ Fix from $1,6002024-09-25 MEDIUM 5.4 CVE-2024-45621 The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate b… Rocket.chat after 6.3.4 Fix from $1,6002024-09-02 HIGH 8.6 CVE-2024-39713 A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1. Rocket.chat 6.10.1+ Fix from $1,9502024-08-05 MEDIUM 5.3 CVE-2023-28359 A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated u… Rocket.chat 6.0.0+ Fix from $1,6002023-05-11 HIGH 7.5 CVE-2023-28356 A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot l… Rocket.chat 6.0.0+ Fix from $1,9502023-05-11 MEDIUM 6.5 CVE-2023-28325 An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMes… Rocket.chat 6.0.0+ Fix from $1,6002023-05-11 MEDIUM 6.1 CVE-2023-28358 A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious … Rocket.chat 6.0.0+ Fix from $1,6002023-05-11 MEDIUM 5.3 CVE-2023-28317 A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in a… Rocket.chat Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.3 CVE-2023-28318 A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus s… Rocket.chat Mitigation only Fix from $1,6002023-05-09 CRITICAL 9.8 CVE-2023-28316 A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidate… Rocket.chat Mitigation only Fix from $2,3002023-05-09 HIGH 7.5 CVE-2023-23911 An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changin… Rocket.chat 6.0.0+ Fix from $1,9502023-03-10 HIGH 8.8 CVE-2023-23917 A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can c… Rocket.chat 5.2.0+ Fix from $1,9502023-02-23 CRITICAL 9.8 CVE-2022-44567 A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChat… Rocket.chat 3.8.14+ Fix from $2,3002022-12-23 HIGH 8.8 CVE-2022-35248 A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when te… Rocket.chat 4.7.5 / 4.8.2+ Fix from $1,9502022-09-23 MEDIUM 5.4 CVE-2022-35251 A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an adversary is able to manipulate… Rocket.chat 5.0+ Fix from $1,6002022-09-23 HIGH 8.8 CVE-2022-32211 A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password token thro… Rocket.chat 3.18.6 / 4.4.4+ Fix from $1,9502022-09-23 MEDIUM 6.8 CVE-2022-30124 An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile dev… Rocket.chat 4.14.1.22788+ Fix from $1,6002022-09-23 MEDIUM 6.5 CVE-2022-32220 An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from pr… Rocket.chat 5.0+ Fix from $1,6002022-09-23