VYPR

Rocket.chat

by RocketChat

npm: rocket.chat

Source repositories

CVEs (83)

  • CVE-2020-15926MedAug 18, 2020
    risk 0.00cvss 6.1epss 0.03

    Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.

  • CVE-2018-13878MedJul 11, 2018
    risk 0.00cvss 6.1epss 0.01

    An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the…

  • CVE-2017-1000493CriJan 3, 2018
    risk 0.00cvss 9.8epss 0.02

    Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

Page 5 of 5