CVE-2026-22560
- EPSS 0.02%
- Veröffentlicht 10.04.2026 17:00:11
- Zuletzt bearbeitet 17.04.2026 22:01:13
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.
CVE-2026-30833
- EPSS 0.02%
- Veröffentlicht 06.03.2026 17:40:36
- Zuletzt bearbeitet 13.03.2026 18:46:27
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in Rocket.Chat's account service used in the ddp-stre...
CVE-2026-30831
- EPSS 0.08%
- Veröffentlicht 06.03.2026 17:40:27
- Zuletzt bearbeitet 13.03.2026 18:52:27
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer service. The A...
CVE-2026-28514
- EPSS 0.05%
- Veröffentlicht 06.03.2026 17:35:01
- Zuletzt bearbeitet 18.03.2026 16:10:07
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account service used ...
CVE-2026-23477
- EPSS 0.03%
- Veröffentlicht 14.01.2026 18:16:05
- Zuletzt bearbeitet 26.01.2026 18:03:24
Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This e...
CVE-2025-7974
- EPSS 0.07%
- Veröffentlicht 02.09.2025 19:46:21
- Zuletzt bearbeitet 27.01.2026 18:39:15
rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of rocket.chat. Authentication is not required to exploit this vulnerabil...
CVE-2025-5892
- EPSS 0.67%
- Veröffentlicht 09.06.2025 19:31:05
- Zuletzt bearbeitet 10.07.2025 16:24:57
A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. The manipulation of the argument lin...
CVE-2024-42027
- EPSS 0.14%
- Veröffentlicht 07.10.2024 13:15:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.
CVE-2024-47048
- EPSS 0.14%
- Veröffentlicht 25.09.2024 01:15:44
- Zuletzt bearbeitet 25.03.2025 17:16:11
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.
CVE-2024-46935
- EPSS 0.1%
- Veröffentlicht 25.09.2024 01:15:44
- Zuletzt bearbeitet 25.03.2025 17:16:10
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.