About “Rocket.Chat”

A curated feed of “Rocket.Chat”-related CVEs appears below. We currently track 7 CVEs for this tag (all time). In the last 365 days, 1 were published. Average CVSS is 5.0 (all time; 4.3 over 365d), and 0% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-400 - Uncontrolled Resource Consumption.

In our taxonomy this topic maps to a MODERATE impact class. CMS and plugins expand attack surface. Patch core, themes, and plugins, remove abandoned extensions, restrict admin access, enable WAF, and keep backups. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

Support & lifecycle: rocket-chat

This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.

CycleReleaseLatestPremier SupportEOLLTS
8.48.4.3 Soon
8.38.3.5 Soon
8.28.2.5 Soon
8.18.1.5 Soon
8.08.0.6 Soon
7.137.13.8 Expired
7.127.12.7 Expired
7.117.11.7 Expired
7.107.10.12 SoonLTS
7.97.9.8 Expired
7.87.8.6 Expired
7.77.7.9 Expired
7.67.6.6 Expired
7.57.5.5 Expired
7.47.4.6 Expired
7.37.3.6 Expired
7.27.2.6 Expired
7.17.1.6 Expired
7.07.0.9 Expired
6.136.13.1 Expired
6.126.12.3 Expired
6.116.11.3 Expired
6.106.10.10 Expired
6.96.9.7 Expired
6.86.8.7 Expired
6.76.7.9 Expired
6.66.6.13 Expired
6.56.5.9 Expired
6.46.4.9 Expired
6.36.3.13 Expired
6.26.2.12 Expired
6.16.1.8 Expired
6.06.0.8 Expired
5.45.4.10 ExpiredLTS
5.35.3.7 Expired
5.25.2.2 Expired
5.15.1.5 Expired
5.05.0.8 Expired
4.84.8.7 ExpiredLTS
4.74.7.5 Expired
4.64.6.4 Expired
4.54.5.7 Expired
4.44.4.5 Expired
4.34.3.3 Expired
4.24.2.4 Expired
4.14.1.6 Expired
4.04.0.6 Expired
3.183.18.7 ExpiredLTS
3.173.17.3 Expired
3.163.16.5 Expired
3.153.15.4 Expired
3.143.14.6 Expired
3.133.13.5 Expired
3.123.12.7 Expired
3.113.11.6 Expired
3.103.10.7 Expired
3.93.9.7 Expired
3.83.8.9 Expired
3.73.7.4 Expired
3.63.6.3 Expired
3.53.5.4 Expired
3.43.4.3 Expired
3.33.3.3 Expired
3.23.2.2 Expired
3.13.1.3 Expired
3.03.0.13 Expired
2.42.4.14 ExpiredLTS
2.32.3.3 Expired
2.22.2.1 Expired
2.12.1.3 Expired
2.02.0.1 Expired
1.31.3.5 ExpiredLTS
1.21.2.4 Expired
1.11.1.5 Expired
1.01.0.5 Expired

Maintained Soon (≤ 180 days) Expired

Subscribe lifecycle: RSS  ·  RSS (expired)  ·  ICS

Subscribe CVEs: RSS for “Rocket.Chat”

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2025-06-09
Medium

CVE-2025-5892

A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/pa…

2022-06-30
Medium

CVE-2022-34802

Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by use…

2022-04-01
Medium

CVE-2022-21830

A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.

2022-03-29
Medium

CVE-2022-28139

A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified cred…

Medium

CVE-2022-28138

A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential.

2018-07-11
Medium

CVE-2018-13879

A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control cha…

Medium

CVE-2018-13878

An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol)…

CVE Daily Lookup — auto-links CVE IDs on any page you visit. GitHub, Jira, Confluence & more. Free.