Rocket.Chat kayıtları
rocket.chat üreticisine ait 64 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %18,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-287 Improper Authentication6
- CWE-284 Improper Access Control4
- CWE-285 Improper Authorization3
- CWE-400 Uncontrolled Resource Consumption3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
64 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2021-22911Kavram kanıtı | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectiorocket.chat · rocket.chat · CWE-75 | Kritik9,8 | — | %95,2 | 27 May 2021 |
40Planlayın | CVE-2021-22910İstismar yok | A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which couldrocket.chat · rocket.chat · CWE-75 | Kritik9,8 | — | %2,3 | 9 Ağu 2021 |
40Planlayın | CVE-2017-1000493İstismar yok | Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeoverrocket.chat · rocket.chat · CWE-74 | Kritik9,8 | — | %1,7 | 2 Oca 2018 |
39İzleyin | CVE-2022-44567İstismar yok | A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalrocket.chat · rocket.chat · CWE-78 | Kritik9,8 | — | %1,7 | 23 Ara 2022 |
39İzleyin | CVE-2020-29594İstismar yok | Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAMLrocket.chat · rocket.chat | Kritik9,8 | — | %1,6 | 30 Ara 2020 |
39İzleyin | CVE-2023-28316İstismar yok | A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not irocket.chat · rocket.chat · CWE-384 | Kritik9,8 | — | %0,7 | 9 May 2023 |
39İzleyin | CVE-2026-29198Kavram kanıtı | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account trocket.chat · rocket.chat · CWE-89 | Kritik9,8 | — | %0,6 | 22 Nis 2026 |
39İzleyin | CVE-2026-58066İstismar yok | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did nrocket.chat · rocket.chat · CWE-287 | Kritik9,8 | — | %0,4 | 30 Tem 2026 |
37İzleyin | CVE-2026-28514İstismar yok | Rocket.Chat: Users can login with any password via the EE ddp-streamer-servicerocket.chat · rocket.chat · CWE-287 | Kritik9,3 | — | %0,7 | 6 Mar 2026 |
37İzleyin | CVE-2026-48616İstismar yok | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.rocket.chat · rocket.chat · CWE-284 | Kritik9,3 | — | %0,4 | 17 Haz 2026 |
35İzleyin | CVE-2024-39713Kavram kanıtı | A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.rocket.chat · rocket.chat · CWE-918 | Yüksek8,6 | — | %3,2 | 5 Ağu 2024 |
35İzleyin | CVE-2022-35248İstismar yok | A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasserocket.chat · rocket.chat · CWE-287 | Yüksek8,8 | — | %1,4 | 23 Eyl 2022 |
35İzleyin | CVE-2022-32211İstismar yok | A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password trocket.chat · rocket.chat · CWE-89 | Yüksek8,8 | — | %1,4 | 23 Eyl 2022 |
35İzleyin | CVE-2023-23917İstismar yok | A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account.rocket.chat · rocket.chat · CWE-77 | Yüksek8,8 | — | %1,0 | 23 Şub 2023 |
32İzleyin | CVE-2026-30831İstismar yok | Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamerrocket.chat · rocket.chat · CWE-287 | Yüksek8,0 | — | %0,6 | 6 Mar 2026 |
31İzleyin | CVE-2021-22892İstismar yok | An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be drocket.chat · rocket.chat · CWE-200 | Yüksek7,5 | — | %1,9 | 27 May 2021 |
30İzleyin | CVE-2026-48929İstismar yok | Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletionrocket.chat · rocket.chat · CWE-287 | Yüksek7,5 | — | %0,9 | 17 Haz 2026 |
30İzleyin | CVE-2020-26763İstismar yok | The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.rocket.chat · rocket.chat | Yüksek7,5 | — | %0,8 | 5 Tem 2021 |
30İzleyin | CVE-2023-28356İstismar yok | A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enterocket.chat · rocket.chat · CWE-400 | Yüksek7,5 | — | %0,7 | 11 May 2023 |
30İzleyin | CVE-2024-46935İstismar yok | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).rocket.chat · rocket.chat | Yüksek7,5 | — | %0,6 | 24 Eyl 2024 |
30İzleyin | CVE-2026-65644İstismar yok | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/liverocket.chat · rocket.chat · CWE-79 | Yüksek7,5 | — | %0,5 | 21 Ağu 2026 |
30İzleyin | CVE-2025-7974İstismar yok | rocket.chat Incorrect Authorization Information Disclosure Vulnerabilityrocket.chat · rocket.chat · CWE-863 | Yüksek7,5 | — | %0,4 | 2 Eyl 2025 |
30İzleyin | CVE-2023-23911İstismar yok | An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a userocket.chat · rocket.chat · CWE-284 | Yüksek7,5 | — | %0,3 | 10 Mar 2023 |
27İzleyin | CVE-2022-30124İstismar yok | An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mrocket.chat · rocket.chat · CWE-287 | Orta6,8 | — | %0,6 | 23 Eyl 2022 |
27İzleyin | CVE-2026-30833İstismar yok | Rocket.Chat: NoSQL injection in the EE ddp-streamer-servicerocket.chat · rocket.chat · CWE-943 | Orta6,9 | — | %0,4 | 6 Mar 2026 |
- CVE-2021-2291168Bu hafta
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio
KritikCVSS 9,8Kavram kanıtıEPSS %95rocket.chat · rocket.chat27 May 2021
- CVE-2021-2291040Planlayın
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could
KritikCVSS 9,8İstismar yokEPSS %2rocket.chat · rocket.chat9 Ağu 2021
- CVE-2017-100049340Planlayın
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
KritikCVSS 9,8İstismar yokEPSS %2rocket.chat · rocket.chat2 Oca 2018
- CVE-2022-4456739İzleyin
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternal
KritikCVSS 9,8İstismar yokEPSS %2rocket.chat · rocket.chat23 Ara 2022
- CVE-2020-2959439İzleyin
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML
KritikCVSS 9,8İstismar yokEPSS %2rocket.chat · rocket.chat30 Ara 2020
- CVE-2023-2831639İzleyin
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not i
KritikCVSS 9,8İstismar yokEPSS %1rocket.chat · rocket.chat9 May 2023
- CVE-2026-2919839İzleyin
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account t
KritikCVSS 9,8Kavram kanıtıEPSS %1rocket.chat · rocket.chat22 Nis 2026
- CVE-2026-5806639İzleyin
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did n
KritikCVSS 9,8İstismar yokEPSS %0rocket.chat · rocket.chat30 Tem 2026
- CVE-2026-2851437İzleyin
Rocket.Chat: Users can login with any password via the EE ddp-streamer-service
KritikCVSS 9,3İstismar yokEPSS %1rocket.chat · rocket.chat6 Mar 2026
- CVE-2026-4861637İzleyin
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.
KritikCVSS 9,3İstismar yokEPSS %0rocket.chat · rocket.chat17 Haz 2026
- CVE-2024-3971335İzleyin
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
YüksekCVSS 8,6Kavram kanıtıEPSS %3rocket.chat · rocket.chat5 Ağu 2024
- CVE-2022-3524835İzleyin
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasse
YüksekCVSS 8,8İstismar yokEPSS %1rocket.chat · rocket.chat23 Eyl 2022
- CVE-2022-3221135İzleyin
A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password t
YüksekCVSS 8,8İstismar yokEPSS %1rocket.chat · rocket.chat23 Eyl 2022
- CVE-2023-2391735İzleyin
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account.
YüksekCVSS 8,8İstismar yokEPSS %1rocket.chat · rocket.chat23 Şub 2023
- CVE-2026-3083132İzleyin
Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer
YüksekCVSS 8,0İstismar yokEPSS %1rocket.chat · rocket.chat6 Mar 2026
- CVE-2021-2289231İzleyin
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be d
YüksekCVSS 7,5İstismar yokEPSS %2rocket.chat · rocket.chat27 May 2021
- CVE-2026-4892930İzleyin
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion
YüksekCVSS 7,5İstismar yokEPSS %1rocket.chat · rocket.chat17 Haz 2026
- CVE-2020-2676330İzleyin
The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
YüksekCVSS 7,5İstismar yokEPSS %1rocket.chat · rocket.chat5 Tem 2021
- CVE-2023-2835630İzleyin
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to ente
YüksekCVSS 7,5İstismar yokEPSS %1rocket.chat · rocket.chat11 May 2023
- CVE-2024-4693530İzleyin
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).
YüksekCVSS 7,5İstismar yokEPSS %1rocket.chat · rocket.chat24 Eyl 2024
- CVE-2026-6564430İzleyin
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/live
YüksekCVSS 7,5İstismar yokEPSS %0rocket.chat · rocket.chat21 Ağu 2026
- CVE-2025-797430İzleyin
rocket.chat Incorrect Authorization Information Disclosure Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0rocket.chat · rocket.chat2 Eyl 2025
- CVE-2023-2391130İzleyin
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a use
YüksekCVSS 7,5İstismar yokEPSS %0rocket.chat · rocket.chat10 Mar 2023
- CVE-2022-3012427İzleyin
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a m
OrtaCVSS 6,8İstismar yokEPSS %1rocket.chat · rocket.chat23 Eyl 2022
- CVE-2026-3083327İzleyin
Rocket.Chat: NoSQL injection in the EE ddp-streamer-service
OrtaCVSS 6,9İstismar yokEPSS %0rocket.chat · rocket.chat6 Mar 2026