Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
rocket.chat rocket.chat vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-22886
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app....
Rocket.chat Rocket.chat
Rocket.chat Rocket.chat 3.11.0
6.1
CVSSv3
CVE-2017-1000054
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages....
Rocketchat Rocket.chat 0.35.0
Rocketchat Rocket.chat 0.34.0
Rocketchat Rocket.chat 0.33.0
Rocketchat Rocket.chat 0.32.0
Rocketchat Rocket.chat 0.18.1
Rocketchat Rocket.chat 0.18.0
Rocketchat Rocket.chat 0.17.0
Rocketchat Rocket.chat 0.16.0
Rocketchat Rocket.chat 0.49.1
Rocketchat Rocket.chat 0.49.0
Rocketchat Rocket.chat 0.48.2
Rocketchat Rocket.chat 0.48.1
Rocketchat Rocket.chat 0.55.1
Rocketchat Rocket.chat 0.54.2
Rocketchat Rocket.chat 0.54.1
Rocketchat Rocket.chat 0.54.0
Rocketchat Rocket.chat 0.53.0
Rocketchat Rocket.chat 0.38.0
Rocketchat Rocket.chat 0.37.0
Rocketchat Rocket.chat 0.30.0
Rocketchat Rocket.chat 0.28.0
Rocketchat Rocket.chat 0.21.0
Rocketchat Rocket.chat 0.19.0
Rocketchat Rocket.chat 0.15.0
Rocketchat Rocket.chat 0.13.0
Rocketchat Rocket.chat 0.9.0
Rocketchat Rocket.chat 0.49.3
Rocketchat Rocket.chat 0.47.1
Rocketchat Rocket.chat 0.46.0
Rocketchat Rocket.chat 0.41.0
Rocketchat Rocket.chat 0.56.0
Rocketchat Rocket.chat 0.52.0
Rocketchat Rocket.chat 0.50.1
Rocketchat Rocket.chat 0.57.1
Rocketchat Rocket.chat 0.8.0
Rocketchat Rocket.chat 0.39.0
Rocketchat Rocket.chat 0.26.0
Rocketchat Rocket.chat 0.25.0
Rocketchat Rocket.chat 0.24.0
Rocketchat Rocket.chat 0.23.0
Rocketchat Rocket.chat 0.12.0
Rocketchat Rocket.chat 0.11.0
Rocketchat Rocket.chat 0.10.2
Rocketchat Rocket.chat 0.10.1
Rocketchat Rocket.chat 0.45.0
Rocketchat Rocket.chat 0.44.0
Rocketchat Rocket.chat 0.43.0
Rocketchat Rocket.chat 0.42.0
Rocketchat Rocket.chat 0.57.0
Rocketchat Rocket.chat 0.37.1
Rocketchat Rocket.chat 0.36.0
Rocketchat Rocket.chat 0.31.0
Rocketchat Rocket.chat 0.29.0
Rocketchat Rocket.chat 0.27.0
Rocketchat Rocket.chat 0.22.0
Rocketchat Rocket.chat 0.20.0
Rocketchat Rocket.chat 0.14.0
Rocketchat Rocket.chat 0.12.1
Rocketchat Rocket.chat 0.10.0
Rocketchat Rocket.chat 0.49.4
Rocketchat Rocket.chat 0.49.2
Rocketchat Rocket.chat 0.48.0
Rocketchat Rocket.chat 0.47.0
Rocketchat Rocket.chat 0.40.1
Rocketchat Rocket.chat 0.55.0
Rocketchat Rocket.chat 0.51.0
Rocketchat Rocket.chat 0.50.0
Rocketchat Rocket.chat 0.57.2
7.5
CVSSv3
CVE-2021-22892
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks....
Rocket.chat Rocket.chat
Rocket.chat Rocket.chat 3.12.3
Rocket.chat Rocket.chat 3.12.4
Rocket.chat Rocket.chat 3.12.5
1 Github repository available
9.8
CVSSv3
CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE....
Rocket.chat Rocket.chat 3.11.0
Rocket.chat Rocket.chat 3.12.0
Rocket.chat Rocket.chat 3.13.0
13 Github repositories available
6.1
CVSSv3
CVE-2020-15926
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side....
Rocket.chat Rocket.chat
1 Github repository available
6.1
CVSSv3
CVE-2019-17220
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line....
Rocket.chat Rocket.chat
1 EDB exploit available
8.8
CVE-2022-35248
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when telling the server to use CAS during login....
Rocket.chat Rocket.chat
1 Github repository available
6.5
CVE-2022-32220
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room....
Rocket.chat Rocket.chat
1 Github repository available
5.3
CVE-2022-32217
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs....
Rocket.chat Rocket.chat
1 Github repository available
9.8
CVSSv3
CVE-2021-22910
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE....
Rocket.chat Rocket.chat
1 Github repository available
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-45441
arbitrary
CVE-2022-31254
CVE-2023-0719
CVE-2023-25136
CVE-2023-0744
CVE-2022-0847
unspecified
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »