Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
rocket.chat rocket.chat vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-44567
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an malicious user to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(), which may lead to remote code execution (internalVideoChatWindow.ts#L17). To exploit the v...
Rocket.chat Rocket.chat
3.5
CVSSv2
CVE-2018-13879
A reflected XSS issue exists in the registration form in Rocket.Chat prior to 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via ...
Rocket.chat Rocket.chat
7.5
CVSSv2
CVE-2021-22910
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
Rocket.chat Rocket.chat
7.5
CVSSv2
CVE-2020-29594
Rocket.Chat prior to 0.74.4, 1.x prior to 1.3.4, 2.x prior to 2.4.13, 3.x prior to 3.7.3, 3.8.x prior to 3.8.3, and 3.9.x prior to 3.9.1 mishandles SAML login.
Rocket.chat Rocket.chat
5
CVSSv2
CVE-2020-28208
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat up to and including 3.9.1.
Rocket.chat Rocket.chat
4.3
CVSSv2
CVE-2018-13878
An XSS issue exists in packages/rocketchat-mentions/Mentions.js in Rocket.Chat prior to 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the secret tok...
Rocket.chat Rocket.chat
3.5
CVSSv2
CVE-2020-8288
The `specializedRendering` function in Rocket.Chat server prior to 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.
Rocket.chat Rocket.chat
4.3
CVSSv2
CVE-2020-8291
A link preview rendering issue in Rocket.Chat versions prior to 3.9 could lead to potential XSS attacks.
Rocket.chat Rocket.chat
4.3
CVSSv2
CVE-2020-8292
Rocket.Chat server prior to 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
Rocket.chat Rocket.chat
4.3
CVSSv2
CVE-2019-17220
Rocket.Chat prior to 2.1.0 allows XSS via a URL on a ![title] line.
Rocket.chat Rocket.chat
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »