Back to Database
Status published
Medium
CVE-2020-15926
Rocket.Chat through 3.4.2 allows XSS where an attacker can send...
Vulnerability Description
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-15926
Credits & Attribution
No credits recorded in the NVD database.
References
More from rocket.chat
View All →CVE-2025-7974
rocket.chat Incorrect Authorization Information Disclosure Vulnerability
Low
3.7
CVE-2020-29594
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x...
Critical
9.8
CVE-2020-28208
An email address enumeration vulnerability exists in the password reset...
Medium
5.3
CVE-2020-26763
The Rocket.Chat desktop application 2.17.11 opens external links without user...
High
7.5
CVE-2019-17220
Rocket.Chat before 2.1.0 allows XSS via a URL on a...
Medium
6.1
Affected Vendor
rocket.chat
View all reports →Affected Software
rocket.chat
Vulnerable Versions:
0
Timeline
Official Publish:
August 18th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.