CVEs (63)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or priva...Show more |
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover |
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages. |