<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Rocket.Chat</title>
  <link>https://cvedaily.com/pages/tags/rocket-chat.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/rocket-chat.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Rocket.Chat</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:06 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2025-5892 – A vulnerability, which was classified as problematic, has been found in RocketCh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5892</guid>
    <pubDate>Mon, 09 Jun 2025 20:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-5892</strong></p>
  <p>A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. The manipulation of the argument line leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be u…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-34802 – Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34802</guid>
    <pubDate>Thu, 30 Jun 2022 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-34802</strong></p>
  <p>Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21830 – A blind self XSS vulnerability exists in RocketChat LiveChat &lt;v1.9 that could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21830</guid>
    <pubDate>Fri, 01 Apr 2022 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21830</strong></p>
  <p>A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28139 – A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28139</guid>
    <pubDate>Tue, 29 Mar 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28139</strong></p>
  <p>A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28138 – A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28138</guid>
    <pubDate>Tue, 29 Mar 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28138</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-13879 – A reflected XSS issue was discovered in the registration form in Rocket.Chat bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13879</guid>
    <pubDate>Wed, 11 Jul 2018 01:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-13879</strong></p>
  <p>A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via packages/rocketchat-ui-login/client/username/username.js in packages/rocketchat-ui-login/client/username/username…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-13878 – An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13878</guid>
    <pubDate>Wed, 11 Jul 2018 01:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-13878</strong></p>
  <p>An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the secret token of every user and also admins in the channel.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13878">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
