Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
rocket.chat rocket.chat vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2021-22892
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
Rocket.chat Rocket.chat
Rocket.chat Rocket.chat 3.12.3
Rocket.chat Rocket.chat 3.12.4
Rocket.chat Rocket.chat 3.12.5
9.8
CVSSv3
CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
Rocket.chat Rocket.chat 3.11.0
Rocket.chat Rocket.chat 3.12.0
Rocket.chat Rocket.chat 3.13.0
10 Github repositories
6.1
CVSSv3
CVE-2017-1000054
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
Rocketchat Rocket.chat 0.11.0
Rocketchat Rocket.chat 0.29.0
Rocketchat Rocket.chat 0.26.0
Rocketchat Rocket.chat 0.23.0
Rocketchat Rocket.chat 0.49.1
Rocketchat Rocket.chat 0.28.0
Rocketchat Rocket.chat 0.16.0
Rocketchat Rocket.chat 0.25.0
Rocketchat Rocket.chat 0.44.0
Rocketchat Rocket.chat 0.57.0
Rocketchat Rocket.chat 0.21.0
Rocketchat Rocket.chat 0.57.2
Rocketchat Rocket.chat 0.37.0
Rocketchat Rocket.chat 0.52.0
Rocketchat Rocket.chat 0.49.4
Rocketchat Rocket.chat 0.54.2
Rocketchat Rocket.chat 0.47.0
Rocketchat Rocket.chat 0.31.0
Rocketchat Rocket.chat 0.55.0
Rocketchat Rocket.chat 0.47.1
Rocketchat Rocket.chat 0.48.0
Rocketchat Rocket.chat 0.18.0
6.1
CVSSv3
CVE-2021-22886
Rocket.Chat prior to 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote malicious user to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop ap...
Rocket.chat Rocket.chat
Rocket.chat Rocket.chat 3.11.0
9.8
CVSSv3
CVE-2023-28316
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an malicious user to maintain access to a compromised account even after 2FA is...
Rocket.chat Rocket.chat -
5.3
CVSSv3
CVE-2023-28317
A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.
Rocket.chat Rocket.chat -
5.3
CVSSv3
CVE-2023-28318
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.
Rocket.chat Rocket.chat -
6.5
CVSSv3
CVE-2023-28325
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.
Rocket.chat Rocket.chat
7.5
CVSSv3
CVE-2023-28356
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot loop on one of the processes, consuming ~120% CPU and rendering the service unresponsive.
Rocket.chat Rocket.chat
4.3
CVSSv3
CVE-2023-28357
A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a us...
Rocket.chat Rocket.chat
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »