CVE-2025-21628 describes a critical SQL injection vulnerability in Chatwoot, affecting versions prior to 3.16.0. Authenticated attackers can exploit unsanitized input in conversation and contact filter endpoints to execute arbitrary SQL commands. This flaw carries a CVSS score of 8.8 (High), indicating a network-based attack with low complexity that can lead to high impact on confidentiality, integrity, and availability. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.16.1, < 3.16.0CPE matchmatch criteria | cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.