Rocket.Chat operates a widely deployed team-communication and messaging platform with a dual product portfolio centered on its core chat application and LiveChat offering, both commonly used in enterprises and small-to-medium businesses for internal and customer-facing collaboration. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs through authentication weaknesses, cross-site scripting and input-handling flaws, and information-disclosure issues that are characteristic of web-facing communication platforms with complex user-management and message-routing architectures. Defenders should track this vendor's release cycles closely given the platform's role in business workflows and prioritize patches addressing authentication and XSS vectors; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rocket.Chat over time
Signals from CVEs in this vendor scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22911CRITICAL A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE. | May 27, 2021 | 9.8 | 91 | NO | YES |
CVE-2024-39713HIGH A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1. | Aug 5, 2024 | 8.6 | 37 | NO | YES |
CVE-2026-48616CRITICAL Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fil | Jun 16, 2026 | 9.3 | 34 | NO | NO |
CVE-2026-28514CRITICAL Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authenticat | Mar 6, 2026 | 9.8 | 34 | NO | NO |
CVE-2020-28208MEDIUM An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1. | Jan 8, 2021 | 5.3 | 33 | NO | YES |
CVE-2023-28316CRITICAL A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This cou | May 9, 2023 | 9.8 | 31 | NO | NO |
CVE-2019-17220MEDIUM Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line. | Oct 21, 2019 | 6.1 | 31 | NO | YES |
CVE-2022-44567CRITICAL A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(), | Dec 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2026-29198CRITICAL In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generat | Apr 23, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-30831CRITICAL Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnera | Mar 6, 2026 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (63 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rocket.Chat.
Media articles that mention a CVE ID that affects a product developed by Rocket.Chat — matched by CVE ID, not by vendor name.