CVE-2026-72919
- EPSS 0.24%
- Veröffentlicht 10.08.2026 21:44:59
- Zuletzt bearbeitet 11.08.2026 15:17:37
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated registered user with the create...
CVE-2026-72918
- EPSS 0.2%
- Veröffentlicht 10.08.2026 21:42:36
- Zuletzt bearbeitet 11.08.2026 17:19:14
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated user to write ar...
CVE-2026-49278
- EPSS 0.24%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 26.06.2026 05:16:28
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-information-by...
CVE-2026-49277
- EPSS 0.22%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 26.06.2026 19:16:41
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth bearer or refresh tokens when a user is deactivated. A deacti...
CVE-2026-47733
- EPSS 0.12%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 25.06.2026 16:16:35
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled src values directly into <a href> and <img src> attributes without protocol sa...
CVE-2026-46423
- EPSS 0.15%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 26.06.2026 05:16:27
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML service provider implementation silently skips both SAML Response and Assert...
CVE-2026-45757
- EPSS 0.22%
- Veröffentlicht 24.06.2026 21:16:54
- Zuletzt bearbeitet 25.06.2026 16:16:35
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through users.deactivateIdle to keep using already-issued ...
CVE-2026-45689
- EPSS 0.31%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 26.06.2026 05:16:27
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbit...
CVE-2026-45688
- EPSS 0.29%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 26.06.2026 05:16:27
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login handler forwards the client-supplied options.cas.credentialToken value ...
CVE-2026-45687
- EPSS 0.21%
- Veröffentlicht 24.06.2026 21:16:53
- Zuletzt bearbeitet 26.06.2026 19:16:40
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMessage DDP method passes the entire attacker-supplied file object into U...