Vulnerabilities (CVE)

Filtered by vendor Rocket.chat Subscribe
Filtered by product Rocket.chat
Total 62 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-13878 1 Rocket.chat 1 Rocket.chat 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the secret token of every user and also admins in the channel.
CVE-2017-1000493 1 Rocket.chat 1 Rocket.chat 2026-06-17 7.5 HIGH 9.8 CRITICAL
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover