Записи Rocket.Chat
64 опубликованных записей вендора rocket.chat.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 18,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-287 Improper Authentication6
- CWE-284 Improper Access Control4
- CWE-285 Improper Authorization3
- CWE-400 Uncontrolled Resource Consumption3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
64 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2021-22911Proof of concept | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectiorocket.chat · rocket.chat · CWE-75 | Критическая9,8 | — | 95,2 % | 27 мая 2021 г. |
40В плане | CVE-2021-22910Эксплойта нет | A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which couldrocket.chat · rocket.chat · CWE-75 | Критическая9,8 | — | 2,3 % | 9 авг. 2021 г. |
40В плане | CVE-2017-1000493Эксплойта нет | Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeoverrocket.chat · rocket.chat · CWE-74 | Критическая9,8 | — | 1,7 % | 2 янв. 2018 г. |
39Наблюдать | CVE-2022-44567Эксплойта нет | A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalrocket.chat · rocket.chat · CWE-78 | Критическая9,8 | — | 1,7 % | 23 дек. 2022 г. |
39Наблюдать | CVE-2020-29594Эксплойта нет | Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAMLrocket.chat · rocket.chat | Критическая9,8 | — | 1,6 % | 30 дек. 2020 г. |
39Наблюдать | CVE-2023-28316Эксплойта нет | A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not irocket.chat · rocket.chat · CWE-384 | Критическая9,8 | — | 0,7 % | 9 мая 2023 г. |
39Наблюдать | CVE-2026-29198Proof of concept | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account trocket.chat · rocket.chat · CWE-89 | Критическая9,8 | — | 0,6 % | 22 апр. 2026 г. |
39Наблюдать | CVE-2026-58066Эксплойта нет | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did nrocket.chat · rocket.chat · CWE-287 | Критическая9,8 | — | 0,4 % | 30 июл. 2026 г. |
37Наблюдать | CVE-2026-28514Эксплойта нет | Rocket.Chat: Users can login with any password via the EE ddp-streamer-servicerocket.chat · rocket.chat · CWE-287 | Критическая9,3 | — | 0,7 % | 6 мар. 2026 г. |
37Наблюдать | CVE-2026-48616Эксплойта нет | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.rocket.chat · rocket.chat · CWE-284 | Критическая9,3 | — | 0,4 % | 17 июн. 2026 г. |
35Наблюдать | CVE-2024-39713Proof of concept | A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.rocket.chat · rocket.chat · CWE-918 | Высокая8,6 | — | 3,2 % | 5 авг. 2024 г. |
35Наблюдать | CVE-2022-35248Эксплойта нет | A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasserocket.chat · rocket.chat · CWE-287 | Высокая8,8 | — | 1,4 % | 23 сент. 2022 г. |
35Наблюдать | CVE-2022-32211Эксплойта нет | A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password trocket.chat · rocket.chat · CWE-89 | Высокая8,8 | — | 1,4 % | 23 сент. 2022 г. |
35Наблюдать | CVE-2023-23917Эксплойта нет | A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account.rocket.chat · rocket.chat · CWE-77 | Высокая8,8 | — | 1,0 % | 23 февр. 2023 г. |
32Наблюдать | CVE-2026-30831Эксплойта нет | Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamerrocket.chat · rocket.chat · CWE-287 | Высокая8,0 | — | 0,6 % | 6 мар. 2026 г. |
31Наблюдать | CVE-2021-22892Эксплойта нет | An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be drocket.chat · rocket.chat · CWE-200 | Высокая7,5 | — | 1,9 % | 27 мая 2021 г. |
30Наблюдать | CVE-2026-48929Эксплойта нет | Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletionrocket.chat · rocket.chat · CWE-287 | Высокая7,5 | — | 0,9 % | 17 июн. 2026 г. |
30Наблюдать | CVE-2020-26763Эксплойта нет | The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.rocket.chat · rocket.chat | Высокая7,5 | — | 0,8 % | 5 июл. 2021 г. |
30Наблюдать | CVE-2023-28356Эксплойта нет | A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enterocket.chat · rocket.chat · CWE-400 | Высокая7,5 | — | 0,7 % | 11 мая 2023 г. |
30Наблюдать | CVE-2024-46935Эксплойта нет | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).rocket.chat · rocket.chat | Высокая7,5 | — | 0,6 % | 24 сент. 2024 г. |
30Наблюдать | CVE-2026-65644Эксплойта нет | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/liverocket.chat · rocket.chat · CWE-79 | Высокая7,5 | — | 0,5 % | 21 авг. 2026 г. |
30Наблюдать | CVE-2025-7974Эксплойта нет | rocket.chat Incorrect Authorization Information Disclosure Vulnerabilityrocket.chat · rocket.chat · CWE-863 | Высокая7,5 | — | 0,4 % | 2 сент. 2025 г. |
30Наблюдать | CVE-2023-23911Эксплойта нет | An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a userocket.chat · rocket.chat · CWE-284 | Высокая7,5 | — | 0,3 % | 10 мар. 2023 г. |
27Наблюдать | CVE-2022-30124Эксплойта нет | An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mrocket.chat · rocket.chat · CWE-287 | Средняя6,8 | — | 0,6 % | 23 сент. 2022 г. |
27Наблюдать | CVE-2026-30833Эксплойта нет | Rocket.Chat: NoSQL injection in the EE ddp-streamer-servicerocket.chat · rocket.chat · CWE-943 | Средняя6,9 | — | 0,4 % | 6 мар. 2026 г. |
- CVE-2021-2291168На этой неделе
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio
КритическаяCVSS 9,8Proof of conceptEPSS 95 %rocket.chat · rocket.chat27 мая 2021 г.
- CVE-2021-2291040В плане
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rocket.chat · rocket.chat9 авг. 2021 г.
- CVE-2017-100049340В плане
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rocket.chat · rocket.chat2 янв. 2018 г.
- CVE-2022-4456739Наблюдать
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternal
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rocket.chat · rocket.chat23 дек. 2022 г.
- CVE-2020-2959439Наблюдать
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rocket.chat · rocket.chat30 дек. 2020 г.
- CVE-2023-2831639Наблюдать
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not i
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rocket.chat · rocket.chat9 мая 2023 г.
- CVE-2026-2919839Наблюдать
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account t
КритическаяCVSS 9,8Proof of conceptEPSS 1 %rocket.chat · rocket.chat22 апр. 2026 г.
- CVE-2026-5806639Наблюдать
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did n
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %rocket.chat · rocket.chat30 июл. 2026 г.
- CVE-2026-2851437Наблюдать
Rocket.Chat: Users can login with any password via the EE ddp-streamer-service
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %rocket.chat · rocket.chat6 мар. 2026 г.
- CVE-2026-4861637Наблюдать
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %rocket.chat · rocket.chat17 июн. 2026 г.
- CVE-2024-3971335Наблюдать
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
ВысокаяCVSS 8,6Proof of conceptEPSS 3 %rocket.chat · rocket.chat5 авг. 2024 г.
- CVE-2022-3524835Наблюдать
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasse
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rocket.chat · rocket.chat23 сент. 2022 г.
- CVE-2022-3221135Наблюдать
A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password t
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rocket.chat · rocket.chat23 сент. 2022 г.
- CVE-2023-2391735Наблюдать
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rocket.chat · rocket.chat23 февр. 2023 г.
- CVE-2026-3083132Наблюдать
Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %rocket.chat · rocket.chat6 мар. 2026 г.
- CVE-2021-2289231Наблюдать
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be d
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %rocket.chat · rocket.chat27 мая 2021 г.
- CVE-2026-4892930Наблюдать
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rocket.chat · rocket.chat17 июн. 2026 г.
- CVE-2020-2676330Наблюдать
The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rocket.chat · rocket.chat5 июл. 2021 г.
- CVE-2023-2835630Наблюдать
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to ente
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rocket.chat · rocket.chat11 мая 2023 г.
- CVE-2024-4693530Наблюдать
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rocket.chat · rocket.chat24 сент. 2024 г.
- CVE-2026-6564430Наблюдать
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/live
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %rocket.chat · rocket.chat21 авг. 2026 г.
- CVE-2025-797430Наблюдать
rocket.chat Incorrect Authorization Information Disclosure Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %rocket.chat · rocket.chat2 сент. 2025 г.
- CVE-2023-2391130Наблюдать
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a use
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %rocket.chat · rocket.chat10 мар. 2023 г.
- CVE-2022-3012427Наблюдать
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a m
СредняяCVSS 6,8Эксплойта нетEPSS 1 %rocket.chat · rocket.chat23 сент. 2022 г.
- CVE-2026-3083327Наблюдать
Rocket.Chat: NoSQL injection in the EE ddp-streamer-service
СредняяCVSS 6,9Эксплойта нетEPSS 0 %rocket.chat · rocket.chat6 мар. 2026 г.