Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rocket.Chat

First CVE: Jan 3, 2018Active for: 9 yearsTotal CVEs: 63
45.8
VTI Score
High

Rocket.Chat operates a widely deployed team-communication and messaging platform with a dual product portfolio centered on its core chat application and LiveChat offering, both commonly used in enterprises and small-to-medium businesses for internal and customer-facing collaboration. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs through authentication weaknesses, cross-site scripting and input-handling flaws, and information-disclosure issues that are characteristic of web-facing communication platforms with complex user-management and message-routing architectures. Defenders should track this vendor's release cycles closely given the platform's role in business workflows and prioritize patches addressing authentication and XSS vectors; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
63
Total CVEs
More Total CVEs than 99% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rocket.Chat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 3, 2018
8 years ago
Most Recent CVE
Jun 16, 2026
38 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-22911CRITICAL
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
May 27, 20219.891NOYES
CVE-2024-39713HIGH
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Aug 5, 20248.637NOYES
CVE-2026-48616CRITICAL
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fil
Jun 16, 20269.334NONO
CVE-2026-28514CRITICAL
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authenticat
Mar 6, 20269.834NONO
CVE-2020-28208MEDIUM
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
Jan 8, 20215.333NOYES
CVE-2023-28316CRITICAL
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This cou
May 9, 20239.831NONO
CVE-2019-17220MEDIUM
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
Oct 21, 20196.131NOYES
CVE-2022-44567CRITICAL
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(),
Dec 23, 20229.830NONO
CVE-2026-29198CRITICAL
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generat
Apr 23, 20269.829NONO
CVE-2026-30831CRITICAL
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnera
Mar 6, 20269.829NONO
View all 63 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products63 CVEs
63%
21%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network62 (98.4%)
Unknown0 (0.0%)
Physical1 (1.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (98.4%)
High1 (1.6%)
Unknown0 (0.0%)
User Interaction
None49 (77.8%)
Unknown0 (0.0%)
Required14 (22.2%)
Privileges Required
Low25 (39.7%)
High0 (0.0%)
None38 (60.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.8% of CVEs· 96th percentile
ExploitDB
2 CVEs
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rocket.Chat.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rocket.Chat — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rocket.Chat's Products

View all 5 CNAs →

Top CWEs