chatwoot vulnerabilities
CVEs whose affected-version data names the chatwoot package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92527Medium· 6.3A vulnerability has been found in chatwoot up to 4.17.1
A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of t…
▾ SunlitEPSS 0.35%via NVD
CVE-2026-63765High· 8.2PoCChatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing au…
▾ Midnightchatwoot · chatwootEPSS 0.70%via NVD