CVE-2023-28318: Rocket.chat

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.

Affected products

  • Rocket.chat Rocket.chat: affected versions not specified

Published 2023-05-09. Last modified 2026-06-17.