Rocketchat

Rocket.Chat

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 06.03.2026 17:40:36
  • Zuletzt bearbeitet 13.03.2026 18:46:27

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in Rocket.Chat's account service used in the ddp-stre...

  • EPSS 0.08%
  • Veröffentlicht 06.03.2026 17:40:27
  • Zuletzt bearbeitet 13.03.2026 18:52:27

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer service. The A...

  • EPSS 0.05%
  • Veröffentlicht 06.03.2026 17:35:01
  • Zuletzt bearbeitet 18.03.2026 16:10:07

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account service used ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 14.01.2026 18:16:05
  • Zuletzt bearbeitet 26.01.2026 18:03:24

Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This e...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 09.06.2025 19:31:05
  • Zuletzt bearbeitet 10.07.2025 16:24:57

A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. The manipulation of the argument lin...

  • EPSS 0.1%
  • Veröffentlicht 25.09.2024 01:15:44
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.

  • EPSS 0.21%
  • Veröffentlicht 17.07.2017 13:18:17
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.