VYPR

Rocket.chat

by RocketChat

npm: rocket.chat

Source repositories

CVEs (80)

  • CVE-2022-35251MedSep 23, 2022
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an adversary is able to manipulate not only the style of it, but will also be able to block functionality as well as hijacking the content of targeted users. Hence…

  • CVE-2020-8292MedJan 26, 2021
    risk 0.35cvss 5.4epss 0.01

    Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.

  • CVE-2020-8288MedJan 26, 2021
    risk 0.35cvss 5.4epss 0.01

    The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.

  • CVE-2020-28208MedJan 8, 2021
    risk 0.35cvss 5.3epss 0.11

    An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.

  • CVE-2018-13879MedJul 11, 2018
    risk 0.35cvss 5.4epss 0.01

    A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username…

  • CVE-2026-32994MedMay 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply…

  • CVE-2026-30833MedMar 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, a NoSQL injection vulnerability exists in Rocket.Chat's account service used in the ddp-streamer micro service that…

  • CVE-2023-28359MedMay 11, 2023
    risk 0.34cvss 5.3epss 0.01

    A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability causes a delay in the server…

  • CVE-2023-28318MedMay 9, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.

  • CVE-2023-28317MedMay 9, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.

  • CVE-2022-32217MedSep 23, 2022
    risk 0.34cvss 5.3epss 0.01

    A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs.

  • CVE-2026-72918MedAug 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated user to write arbitrary notification bodies…

  • CVE-2025-5892MedJun 9, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. The manipulation of the argument line leads to inefficient…

  • CVE-2023-28357MedMay 11, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a…

  • CVE-2022-35250MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to view Direct messages without appropriate permissions.

  • CVE-2022-35249MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

  • CVE-2022-35247MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles Meteor method leak channel members with special roles to unauthorized clients.

  • CVE-2022-35246MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to access.

  • CVE-2022-32229MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A information disclosure vulnerability exists in Rockert.Chat <v5 due to /api/v1/chat.getThreadsList lack of sanitization of user inputs and can therefore leak private thread messages to unauthorized users via Mongo DB injection.

  • CVE-2022-32228MedSep 23, 2022
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 since the getReadReceipts Meteor server method does not properly filter user inputs that are passed to MongoDB queries, allowing $regex queries to enumerate arbitrary Message IDs.