📦

rocket.chat

Vendor: rocket.chat

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 7 Remote Access
Total CVEs 71 Total Indexed
Avg. EPSS 2.63% Exploit Prob.
Latest CVE CVE-2026-48929 Jun 17

Security Vulnerability Index

Page 5 / 8
5.3 CVSS

A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs.

EPSS: 0.55%
8.8 CVSS

A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password token through or a 2fa secret.

EPSS: 1.08%
6.8 CVSS

An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).

EPSS: 0.56%
6.1 CVSS

A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.

EPSS: 0.61%
4.3 CVSS

Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13.

EPSS: 1.57%
9.8 CVSS

A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.

EPSS: 2.26%
7.5 CVSS

The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.

EPSS: 0.82%
9.8 CVSS
CVE-2021-22911
RCE Exploit Found

A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.

EPSS: 95.24%
7.5 CVSS

An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.

EPSS: 1.86%
6.1 CVSS

Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.

EPSS: 1.70%