chatwoot
Communicationsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting chatwoot.
- CVE-2026-63765Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation8.2
- CVE-2026-44707Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts6.8
- CVE-2026-44706Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values8.5
- CVE-2025-12246chatwoot Admin IframeLoader.vue cross site scripting4.3
- CVE-2025-12245chatwoot Widget IFrameHelper.js initPostMessageCommunication origin validation5.3
- CVE-2024-0640Stored XSS in chatwoot/chatwoot4.8
- CVE-2025-21628Chatwoot has a Blind SQL-injection in Conversation and Contacts filters9.1
- CVE-2021-3740Session Fixation in chatwoot/chatwoot6.8
- CVE-2021-3742Server-Side Request Forgery (SSRF) in chatwoot/chatwoot8.8
- CVE-2021-3741Stored Cross-site Scripting (XSS) in chatwoot/chatwoot5.4
- CVE-2023-2109Cross-site Scripting (XSS) - DOM in chatwoot/chatwoot6.1
- CVE-2022-3741Improper Restriction of Excessive Authentication Attempts in chatwoot/chatwoot9.8
- CVE-2022-2901Improper Authorization in chatwoot/chatwoot7.1
- CVE-2022-0542Cross-site Scripting (XSS) - DOM in chatwoot/chatwoot6.1
- CVE-2022-1021Insecure Storage of Sensitive Information in chatwoot/chatwoot5.4