📦 Chatwoot

by Chatwoot

🔍 What is Chatwoot?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-21628

CRITICAL CVSS 9.1 Jan 9, 2025

This SQL injection vulnerability in Chatwoot allows authenticated users to execute arbitrary SQL queries through conversation and contact filter endpoints. Attackers can bypass intended filters and po...

CVE-2021-3742

HIGH CVSS 8.8 Nov 15, 2024

This Server-Side Request Forgery (SSRF) vulnerability in Chatwoot allows attackers to upload malicious SVG files containing SSRF payloads. When these files are used as avatars and opened in new tabs, ...

CVE-2021-3649

HIGH CVSS 7.5 Jul 16, 2021

CVE-2021-3649 is a regular expression denial of service (ReDoS) vulnerability in Chatwoot's URL validation logic. Attackers can cause CPU exhaustion and service degradation by sending specially crafte...

CVE-2025-12246

MEDIUM CVSS 4.3 Oct 27, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Chatwoot's admin interface that allows attackers to inject malicious scripts via manipulated Link parameters in the IframeLoader.vue co...

CVE-2025-12245

MEDIUM CVSS 5.3 Oct 27, 2025

This CVE describes an origin validation vulnerability in Chatwoot's widget SDK that allows attackers to bypass security controls by manipulating the baseUrl parameter. The vulnerability affects Chatwo...

CVE-2024-0640

MEDIUM CVSS 4.8 Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability in Chatwoot allows admin users to inject malicious JavaScript code via dashboard app settings. This code executes when other admin users access the af...

CVE-2021-3741

MEDIUM CVSS 5.4 Nov 15, 2024

This stored XSS vulnerability in Chatwoot allows attackers to upload malicious SVG files containing JavaScript payloads via profile settings. When victims view these avatars in a new page, the malicio...