CVE Tools

Rocket-chat

31 CVEs tracked since 2021. Since Jan 2021, none of them reached CISA KEV.

Rocket-chat CVEs per month

Jan 2021 to Sep 2024. Point at a month, or focus the strip and use the arrow keys.
Rocket-chat CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0130
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09160
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-0580
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-0940

Products

The products that kept showing up in Rocket-chat's monthly top three, with their CVEs summed over those months.

  1. Rocket.chat314 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Rocket-chat.

  1. CVE-2026-75575Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method5.3
  2. CVE-2026-65644Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized...7.5
  3. CVE-2026-65645Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped par...4.3
  4. CVE-2026-72919Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams4.3
  5. CVE-2026-72918Rocket.Chat: Insecure implementation of websocket notifications5.4
  6. CVE-2026-56845An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker...7.5
  7. CVE-2026-58066Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:...9.8
  8. CVE-2026-55762Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint8.1
  9. CVE-2026-55759Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay7.4
  10. CVE-2026-55666Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth—
  11. CVE-2026-49278Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation6.7
  12. CVE-2026-49277Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation—
  13. CVE-2026-45757Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens—
  14. CVE-2026-46423Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty—
  15. CVE-2026-45689Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO9.1

The record

Peak rank
#49 in Sep 2022
Busiest month shown
Sep 2022, 16 CVEs
Months with a KEV entry
0 since Jan 2021
Monthly snapshots
4 since 2021
Rocket-chat's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store