Chatwoot

Chatwoot

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 10.08.2026 15:38:09
  • Zuletzt bearbeitet 13.08.2026 18:18:16

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could ...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 23.07.2026 17:52:10
  • Zuletzt bearbeitet 27.07.2026 17:16:39

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication ...

  • EPSS 0.34%
  • Veröffentlicht 26.05.2026 17:10:08
  • Zuletzt bearbeitet 24.07.2026 11:10:00

Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker ...

  • EPSS 0.23%
  • Veröffentlicht 26.05.2026 17:07:41
  • Zuletzt bearbeitet 24.07.2026 11:10:00

Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type date or number using the is_greater_than or is_less_t...

  • EPSS 0.26%
  • Veröffentlicht 31.03.2026 16:30:11
  • Zuletzt bearbeitet 24.07.2026 20:10:00

A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to server-side ...

  • EPSS 0.35%
  • Veröffentlicht 27.03.2026 21:27:18
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argument signupEnabled with the input true leads to imp...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 27.10.2025 07:32:09
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/IframeLoader.vue of the component Admin Interface. The manipulation of the argument Link results in c...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 27.10.2025 07:32:07
  • Zuletzt bearbeitet 28.10.2025 02:15:11

A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to ori...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 20.03.2025 10:10:52
  • Zuletzt bearbeitet 28.10.2025 18:15:12

A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard app settings, which can then be executed by another a...

  • EPSS 0.67%
  • Veröffentlicht 09.01.2025 18:15:30
  • Zuletzt bearbeitet 29.10.2025 14:52:40

Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator passed from the frontend or the API. This provided any actor who is authenticated, an attack vector to r...