CVE-2025-5892
A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/pa…
All CVEs associated with "Rocket.Chat". Page 1/1 • 7 CVEs.
A curated feed of “Rocket.Chat”-related CVEs appears below. We currently track 7 CVEs for this tag (all time). In the last 365 days, 1 were published. Average CVSS is 5.0 (all time; 4.3 over 365d), and 0% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-400 - Uncontrolled Resource Consumption.
In our taxonomy this topic maps to a MODERATE impact class. CMS and plugins expand attack surface. Patch core, themes, and plugins, remove abandoned extensions, restrict admin access, enable WAF, and keep backups. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | Premier Support | EOL | LTS |
|---|---|---|---|---|---|
| 8.4 | 8.4.3 | Soon | |||
| 8.3 | 8.3.5 | Soon | |||
| 8.2 | 8.2.5 | Soon | |||
| 8.1 | 8.1.5 | Soon | |||
| 8.0 | 8.0.6 | Soon | |||
| 7.13 | 7.13.8 | Expired | |||
| 7.12 | 7.12.7 | Expired | |||
| 7.11 | 7.11.7 | Expired | |||
| 7.10 | 7.10.12 | Soon | LTS | ||
| 7.9 | 7.9.8 | Expired | |||
| 7.8 | 7.8.6 | Expired | |||
| 7.7 | 7.7.9 | Expired | |||
| 7.6 | 7.6.6 | Expired | |||
| 7.5 | 7.5.5 | Expired | |||
| 7.4 | 7.4.6 | Expired | |||
| 7.3 | 7.3.6 | Expired | |||
| 7.2 | 7.2.6 | Expired | |||
| 7.1 | 7.1.6 | Expired | |||
| 7.0 | 7.0.9 | Expired | |||
| 6.13 | 6.13.1 | Expired | |||
| 6.12 | 6.12.3 | Expired | |||
| 6.11 | 6.11.3 | Expired | |||
| 6.10 | 6.10.10 | Expired | |||
| 6.9 | 6.9.7 | Expired | |||
| 6.8 | 6.8.7 | Expired | |||
| 6.7 | 6.7.9 | Expired | |||
| 6.6 | 6.6.13 | Expired | |||
| 6.5 | 6.5.9 | Expired | |||
| 6.4 | 6.4.9 | Expired | |||
| 6.3 | 6.3.13 | Expired | |||
| 6.2 | 6.2.12 | Expired | |||
| 6.1 | 6.1.8 | Expired | |||
| 6.0 | 6.0.8 | Expired | |||
| 5.4 | 5.4.10 | Expired | LTS | ||
| 5.3 | 5.3.7 | Expired | |||
| 5.2 | 5.2.2 | Expired | |||
| 5.1 | 5.1.5 | Expired | |||
| 5.0 | 5.0.8 | Expired | |||
| 4.8 | 4.8.7 | Expired | LTS | ||
| 4.7 | 4.7.5 | Expired | |||
| 4.6 | 4.6.4 | Expired | |||
| 4.5 | 4.5.7 | Expired | |||
| 4.4 | 4.4.5 | Expired | |||
| 4.3 | 4.3.3 | Expired | |||
| 4.2 | 4.2.4 | Expired | |||
| 4.1 | 4.1.6 | Expired | |||
| 4.0 | 4.0.6 | Expired | |||
| 3.18 | 3.18.7 | Expired | LTS | ||
| 3.17 | 3.17.3 | Expired | |||
| 3.16 | 3.16.5 | Expired | |||
| 3.15 | 3.15.4 | Expired | |||
| 3.14 | 3.14.6 | Expired | |||
| 3.13 | 3.13.5 | Expired | |||
| 3.12 | 3.12.7 | Expired | |||
| 3.11 | 3.11.6 | Expired | |||
| 3.10 | 3.10.7 | Expired | |||
| 3.9 | 3.9.7 | Expired | |||
| 3.8 | 3.8.9 | Expired | |||
| 3.7 | 3.7.4 | Expired | |||
| 3.6 | 3.6.3 | Expired | |||
| 3.5 | 3.5.4 | Expired | |||
| 3.4 | 3.4.3 | Expired | |||
| 3.3 | 3.3.3 | Expired | |||
| 3.2 | 3.2.2 | Expired | |||
| 3.1 | 3.1.3 | Expired | |||
| 3.0 | 3.0.13 | Expired | |||
| 2.4 | 2.4.14 | Expired | LTS | ||
| 2.3 | 2.3.3 | Expired | |||
| 2.2 | 2.2.1 | Expired | |||
| 2.1 | 2.1.3 | Expired | |||
| 2.0 | 2.0.1 | Expired | |||
| 1.3 | 1.3.5 | Expired | LTS | ||
| 1.2 | 1.2.4 | Expired | |||
| 1.1 | 1.1.5 | Expired | |||
| 1.0 | 1.0.5 | Expired |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Rocket.Chat”
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/pa…
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by use…
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified cred…
A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential.
A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control cha…
An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol)…