Chatwoot

Chatwoot

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 26.05.2026 17:10:08
  • Zuletzt bearbeitet 26.05.2026 19:37:00

Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enforced before an account became usable, an attacker ...

  • EPSS 0.23%
  • Veröffentlicht 26.05.2026 17:07:41
  • Zuletzt bearbeitet 26.05.2026 19:37:00

Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type date or number using the is_greater_than or is_less_t...

  • EPSS 0.22%
  • Veröffentlicht 31.03.2026 16:30:11
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to server-side ...

  • EPSS 0.35%
  • Veröffentlicht 27.03.2026 21:27:18
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argument signupEnabled with the input true leads to imp...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 27.10.2025 07:32:09
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/IframeLoader.vue of the component Admin Interface. The manipulation of the argument Link results in c...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 27.10.2025 07:32:07
  • Zuletzt bearbeitet 28.10.2025 02:15:11

A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to ori...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 20.03.2025 10:10:52
  • Zuletzt bearbeitet 28.10.2025 18:15:12

A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard app settings, which can then be executed by another a...

  • EPSS 0.65%
  • Veröffentlicht 09.01.2025 18:15:30
  • Zuletzt bearbeitet 29.10.2025 14:52:40

Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator passed from the frontend or the API. This provided any actor who is authenticated, an attack vector to r...

  • EPSS 0.37%
  • Veröffentlicht 15.11.2024 11:15:05
  • Zuletzt bearbeitet 19.11.2024 17:10:48

A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG file containing a malicious SSRF payload. When the SVG file is used a...

  • EPSS 0.29%
  • Veröffentlicht 15.11.2024 11:15:05
  • Zuletzt bearbeitet 19.11.2024 17:07:38

A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malicious XSS payload in the profile settings. When the ...