Rocket.Chat
Rocket.chat · 66 CVEs
Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method
Aug 25, 2026
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpo…
Aug 21, 2026
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP meth…
Aug 21, 2026
Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Tea…
Aug 10, 2026
Rocket.Chat: Insecure implementation of websocket notifications
Aug 10, 2026
An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configu…
Aug 4, 2026
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML…
Jul 30, 2026
Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v…
Jun 24, 2026
Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay
Jun 24, 2026
Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth
Jun 24, 2026
Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation
Jun 24, 2026
Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation
Jun 24, 2026
Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens
Jun 24, 2026
Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty
Jun 24, 2026
Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO
Jun 24, 2026
Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack
Jun 24, 2026
Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage
Jun 24, 2026
Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS
Jun 24, 2026
Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images
Jun 24, 2026
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in…
Jun 16, 2026
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthen…
Jun 16, 2026
The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <…
May 28, 2026
The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8…
May 19, 2026
In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/lo…
Apr 23, 2026
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability…
Apr 22, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-75575 | Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method | MEDIUM | 0.40% | Aug 25, 2026 |
| CVE-2026-65644 | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that a… | HIGH | 0.48% | Aug 21, 2026 |
| CVE-2026-65645 | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages… | MEDIUM | 0.34% | Aug 21, 2026 |
| CVE-2026-72919 | Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams | MEDIUM | 0.33% | Aug 10, 2026 |
| CVE-2026-72918 | Rocket.Chat: Insecure implementation of websocket notifications | MEDIUM | 0.22% | Aug 10, 2026 |
| CVE-2026-56845 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequ… | HIGH | 0.60% | Aug 4, 2026 |
| CVE-2026-58066 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validat… | CRITICAL | 0.38% | Jul 30, 2026 |
| CVE-2026-55762 | Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint | HIGH | 0.47% | Jun 24, 2026 |
| CVE-2026-55759 | Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay | HIGH | 0.32% | Jun 24, 2026 |
| CVE-2026-55666 | Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth | CRITICAL | 0.41% | Jun 24, 2026 |
| CVE-2026-49278 | Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation | MEDIUM | 0.41% | Jun 24, 2026 |
| CVE-2026-49277 | Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation | LOW | 0.31% | Jun 24, 2026 |
| CVE-2026-45757 | Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens | LOW | 0.31% | Jun 24, 2026 |
| CVE-2026-46423 | Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty | CRITICAL | 0.22% | Jun 24, 2026 |
| CVE-2026-45689 | Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO | CRITICAL | 0.53% | Jun 24, 2026 |
| CVE-2026-45688 | Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack | CRITICAL | 0.49% | Jun 24, 2026 |
| CVE-2026-45687 | Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage | HIGH | 0.34% | Jun 24, 2026 |
| CVE-2026-45677 | Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS | HIGH | 0.68% | Jun 24, 2026 |
| CVE-2026-47733 | Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images | MEDIUM | 0.18% | Jun 24, 2026 |
| CVE-2026-48616 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads… | CRITICAL | 0.39% | Jun 16, 2026 |
| CVE-2026-48929 | Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMes… | HIGH | 0.86% | Jun 16, 2026 |
| CVE-2026-32995 | The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-su… | HIGH | 0.48% | May 28, 2026 |
| CVE-2026-32994 | The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated… | MEDIUM | 0.30% | May 19, 2026 |
| CVE-2026-29197 | In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in… | MEDIUM | 0.31% | Apr 23, 2026 |
| CVE-2026-29198 | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the firs… | CRITICAL | 0.56% | Apr 22, 2026 |
Showing 1 to 25 of 66 CVEs