Rocket.Chat Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Rocket.Chat products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

0

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

Rocket.Chat KEVs Added by Year

Loading...

2 Rocket.Chat KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2024-39713

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

High Not in CISA 07 Jun 2026
CVE-2021-22911

A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection,...

High Not in CISA 03 Oct 2025

Common Vulnerability Classes (CWE)

  • CWE-75 — Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) 1
  • CWE-918 — Server-Side Request Forgery (SSRF) 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology