CVE-2020-15926: Rocket.chat

Medium severity, CVSS 6.1. EPSS: 2.8% chance of exploitation in the next 30 days.

Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.

Affected products

Published 2020-08-18. Last modified 2026-06-17.