Product
chatwoot
17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-12246
CVE-2025-12245
CVE-2024-0640
CVE-2025-21628
CVE-2021-3742
CVE-2021-3741
CVE-2021-3740
CVE-2023-2109
CVE-2022-3741
CVE-2022-2901
CVE-2022-0542
CVE-2022-1021
CVE-2022-1022
CVE-2021-3813
CVE-2022-0527
CVE-2022-0526
CVE-2021-3649
<= 4.7.0
A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript
<= 4.7.0
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of th
< 3.5.2
A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows a
>= 2.16.1 and < 3.16.0
Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of
< 2.5.0
A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The
< 2.6.0
A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vu
< 2.4.0
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing
< 2.14.0
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.
< 2.10.0
Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on t
< 2.8.0
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
< 2.7.0
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.
< 2.6.0
Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.
< 2.5.0
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
<= 2.1.1
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
<= 2.1.1
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
<= 2.1.1
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
< 1.18.0
chatwoot is vulnerable to Inefficient Regular Expression Complexity