CVE-2020-15926: Rocket.chat
Medium severity, CVSS 6.1. EPSS: 2.8% chance of exploitation in the next 30 days.
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
Affected products
- Rocket.chat Rocket.chat: up to and including 3.4.2
Published 2020-08-18. Last modified 2026-06-17.