CVE-2026-29198
- EPSS 0.42%
- Veröffentlicht 22.04.2026 23:30:15
- Zuletzt bearbeitet 13.05.2026 20:39:44
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.
CVE-2026-22560
- EPSS 0.32%
- Veröffentlicht 10.04.2026 17:00:11
- Zuletzt bearbeitet 17.04.2026 22:01:13
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.
CVE-2026-30833
- EPSS 0.27%
- Veröffentlicht 06.03.2026 17:40:36
- Zuletzt bearbeitet 13.03.2026 18:46:27
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in Rocket.Chat's account service used in the ddp-stre...
CVE-2026-30831
- EPSS 0.33%
- Veröffentlicht 06.03.2026 17:40:27
- Zuletzt bearbeitet 13.03.2026 18:52:27
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer service. The A...
CVE-2026-28514
- EPSS 0.5%
- Veröffentlicht 06.03.2026 17:35:01
- Zuletzt bearbeitet 18.03.2026 16:10:07
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocket.Chat's account service used ...
CVE-2026-23477
- EPSS 0.31%
- Veröffentlicht 14.01.2026 18:16:05
- Zuletzt bearbeitet 26.01.2026 18:03:24
Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This e...
CVE-2025-7974
- EPSS 0.41%
- Veröffentlicht 02.09.2025 19:46:21
- Zuletzt bearbeitet 27.01.2026 18:39:15
rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of rocket.chat. Authentication is not required to exploit this vulnerabil...
CVE-2025-5892
- EPSS 0.53%
- Veröffentlicht 09.06.2025 19:31:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. The manipulation of the argument lin...
CVE-2024-42027
- EPSS 0.55%
- Veröffentlicht 07.10.2024 13:15:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.
CVE-2024-47048
- EPSS 0.36%
- Veröffentlicht 25.09.2024 01:15:44
- Zuletzt bearbeitet 25.03.2025 17:16:11
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.