Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chatwoot MEDIUM 6.1
CVE-2025-12246

A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/…

Fix: after 4.7.0
Fix from $1,600 2025-10-27
Chatwoot MEDIUM 5.3
CVE-2025-12245

A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascri…

Fix: after 4.7.0
Fix from $1,600 2025-10-27
Chatwoot HIGH 8.8
CVE-2025-21628

Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator pas…

Fix: 3.16.0+
Fix from $1,950 2025-01-09
Chatwoot HIGH 8.8
CVE-2021-3742

A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allo…

Fix: 2.5.0+
Fix from $1,950 2024-11-15
Chatwoot MEDIUM 5.4
CVE-2021-3741

A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs …

Fix: 2.6.0+
Fix from $1,600 2024-11-15
Chatwoot MEDIUM 6.8
CVE-2021-3740

A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other …

Fix: 2.4.0+
Fix from $1,600 2024-11-15
Chatwoot MEDIUM 6.1
CVE-2023-2109

Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.

Fix: 2.14.0+
Fix from $1,600 2023-04-17
Chatwoot CRITICAL 9.8
CVE-2022-3741

Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system…

Fix: 2.10.0+
Fix from $2,300 2022-10-28
Chatwoot HIGH 7.1
CVE-2022-2901

Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

Fix: 2.8.0+
Fix from $1,950 2022-09-06
Chatwoot MEDIUM 6.1
CVE-2022-0542

Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.

Fix: 2.7.0+
Fix from $1,600 2022-08-19
Chatwoot MEDIUM 5.4
CVE-2022-1021

Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.

Fix: 2.6.0+
Fix from $1,600 2022-08-19
Chatwoot MEDIUM 5.4
CVE-2022-1022

Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.

Fix: 2.5.0+
Fix from $1,600 2022-04-21
Chatwoot MEDIUM 6.5
CVE-2021-3813

Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.

Fix: after 2.1.1
Fix from $1,600 2022-02-09
Chatwoot MEDIUM 6.1
CVE-2022-0526

Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

Fix: after 2.1.1
Fix from $1,600 2022-02-09
Chatwoot MEDIUM 6.1
CVE-2022-0527

Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

Fix: after 2.1.1
Fix from $1,600 2022-02-09
Chatwoot HIGH 7.5
CVE-2021-3649

chatwoot is vulnerable to Inefficient Regular Expression Complexity

Fix: 1.18.0+
Fix from $1,950 2021-07-16