Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
rocket.chat rocket.chat - vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-28325
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.
Rocket.chat Rocket.chat
3.5
CVSSv2
CVE-2020-8288
The `specializedRendering` function in Rocket.Chat server prior to 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.
Rocket.chat Rocket.chat
4.3
CVSSv2
CVE-2020-8291
A link preview rendering issue in Rocket.Chat versions prior to 3.9 could lead to potential XSS attacks.
Rocket.chat Rocket.chat
4.3
CVSSv2
CVE-2020-8292
Rocket.Chat server prior to 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
Rocket.chat Rocket.chat
3.5
CVSSv2
CVE-2018-13879
A reflected XSS issue exists in the registration form in Rocket.Chat prior to 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via ...
Rocket.chat Rocket.chat
7.5
CVSSv2
CVE-2020-29594
Rocket.Chat prior to 0.74.4, 1.x prior to 1.3.4, 2.x prior to 2.4.13, 3.x prior to 3.7.3, 3.8.x prior to 3.8.3, and 3.9.x prior to 3.9.1 mishandles SAML login.
Rocket.chat Rocket.chat
7.5
CVSSv2
CVE-2021-22910
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
Rocket.chat Rocket.chat
4.3
CVSSv2
CVE-2019-17220
Rocket.Chat prior to 2.1.0 allows XSS via a URL on a ![title] line.
Rocket.chat Rocket.chat
1 EDB exploit
7.5
CVSSv2
CVE-2017-1000493
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
Rocket.chat Rocket.chat
5
CVSSv2
CVE-2020-28208
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat up to and including 3.9.1.
Rocket.chat Rocket.chat
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »