{"api_version":"v1","generated_at":"2026-10-08T20:15:00+00:00","product":{"cve_count":5,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-chatwoot-chatwoot-78294606c23a","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/chatwoot","name":"chatwoot","next_cursor":null,"observations":[{"affected":"< 4.9.0","affected_versions_present":true,"cve_id":"CVE-2026-72719","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-72719","fixed":"4.9.0.","last_modified":"2026-08-13T17:53:07.680Z","patch_url":"https://github.com/chatwoot/chatwoot/security/advisories/GHSA-x288-jh8j-348c","primary_source":"","published":"2026-08-10T15:38:09.970Z"},{"affected":"chatwoot: < 4.16.0","affected_versions_present":true,"cve_id":"CVE-2026-63765","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63765","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T17:54:33.161Z","patch_url":"","primary_source":"","published":"2026-07-23T17:52:10.785Z"},{"affected":">= 2.14.0, < 4.13.0","affected_versions_present":true,"cve_id":"CVE-2026-44707","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44707","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T17:23:05.939Z","patch_url":"","primary_source":"","published":"2026-05-26T17:10:08.478Z"},{"affected":">= 2.2.0, < 4.11.2","affected_versions_present":true,"cve_id":"CVE-2026-44706","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44706","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T18:55:03.847Z","patch_url":"","primary_source":"","published":"2026-05-26T17:07:41.751Z"},{"affected":">= 2.16.1, < 3.16.0","affected_versions_present":true,"cve_id":"CVE-2025-21628","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-21628","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-01-09T18:10:11.074Z","patch_url":"https://github.com/chatwoot/chatwoot/security/advisories/GHSA-g8f9-hh83-rcq9","primary_source":"","published":"2025-01-09T17:10:05.301Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"chatwoot"}}
