CVE-2020-28208: Rocket.chat
Medium severity, CVSS 5.3. EPSS: 10.8% chance of exploitation in the next 30 days.
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
Affected products
- Rocket.chat Rocket.chat: up to and including 3.9.1
Published 2021-01-08. Last modified 2026-06-17.