Rocket.Chat

Rocket.chat · 66 CVEs

CVE-2026-75575
MEDIUM

Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method

Aug 25, 2026

CVE-2026-65644
HIGH

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpo…

Aug 21, 2026

CVE-2026-65645
MEDIUM

Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP meth…

Aug 21, 2026

CVE-2026-72919
MEDIUM

Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Tea…

Aug 10, 2026

CVE-2026-72918
MEDIUM

Rocket.Chat: Insecure implementation of websocket notifications

Aug 10, 2026

CVE-2026-56845
HIGH

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configu…

Aug 4, 2026

CVE-2026-58066
CRITICAL

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML…

Jul 30, 2026

CVE-2026-55762
HIGH

Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v…

Jun 24, 2026

CVE-2026-55759
HIGH

Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay

Jun 24, 2026

CVE-2026-55666
CRITICAL

Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth

Jun 24, 2026

CVE-2026-49278
MEDIUM

Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation

Jun 24, 2026

CVE-2026-49277
LOW

Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation

Jun 24, 2026

CVE-2026-45757
LOW

Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens

Jun 24, 2026

CVE-2026-46423
CRITICAL

Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty

Jun 24, 2026

CVE-2026-45689
CRITICAL

Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO

Jun 24, 2026

CVE-2026-45688
CRITICAL

Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack

Jun 24, 2026

CVE-2026-45687
HIGH

Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage

Jun 24, 2026

CVE-2026-45677
HIGH

Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS

Jun 24, 2026

CVE-2026-47733
MEDIUM

Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images

Jun 24, 2026

CVE-2026-48616
CRITICAL

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in…

Jun 16, 2026

CVE-2026-48929
HIGH

Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthen…

Jun 16, 2026

CVE-2026-32995
HIGH

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <…

May 28, 2026

CVE-2026-32994
MEDIUM

The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8…

May 19, 2026

CVE-2026-29197
MEDIUM

In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/lo…

Apr 23, 2026

CVE-2026-29198
CRITICAL

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability…

Apr 22, 2026

Showing 1 to 25 of 66 CVEs