📦

rocket.chat

Vendor: rocket.chat

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 7 Remote Access
Total CVEs 71 Total Indexed
Avg. EPSS 2.63% Exploit Prob.
Latest CVE CVE-2026-48929 Jun 17

Security Vulnerability Index

Page 6 / 8
5.4 CVSS

Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.

EPSS: 0.90%
5.4 CVSS

The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.

EPSS: 0.85%
5.3 CVSS

An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.

EPSS: 11.42%
9.8 CVSS

Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.

EPSS: 1.61%
6.1 CVSS

Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.

EPSS: 2.82%
6.1 CVSS
CVE-2019-17220
Exploit Found

Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.

EPSS: 4.02%
5.4 CVSS

A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via packages/rocketchat-ui-login/client/username/username.js in packages/rocketchat-ui-login/client/username/username.html.

EPSS: 0.62%
6.1 CVSS

An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the secret token of every user and also admins in the channel.

EPSS: 0.76%
9.8 CVSS

Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

EPSS: 1.73%