Skip to main content

Vendor archive

zulip CVEs

Beta · best-effort

62 CVEs tagged to vendor zulip2 Critical, 11 High, 42 Medium, 7 Low, 0 Unrated.

CVE-2026-40300

Published May 12, 2026

Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26058

Published Apr 3, 2026

Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-25742

Published Apr 3, 2026

Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, even after spec…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-24050

Published Feb 6, 2026

Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel…

CVSS 1.1 · Low
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-52559

Published Jul 2, 2025

Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-47930

Published May 16, 2025

Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvente…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2025-31478

Published Apr 16, 2025

Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authen…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-30369

Published Mar 31, 2025

Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its han…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-30368

Published Mar 31, 2025

Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to…

CVSS 2.7 · Low
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-27149

Published Mar 31, 2025

Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks p…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-56136

Published Jan 16, 2025

Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36624

Published Nov 29, 2024

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36625

Published Nov 29, 2024

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27286

Published Mar 20, 2024

Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21630

Published Jan 25, 2024

Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47642

Published Nov 16, 2023

Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly conti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32678

Published Aug 25, 2023

Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33186

Published May 30, 2023

Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28623

Published May 19, 2023

Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32677

Published May 19, 2023

Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately t…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22735

Published Feb 7, 2023

Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68b` users could upload files with arbitrary `Content-Type` w…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41914

Published Nov 16, 2022

Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-36048

Published Aug 31, 2022

Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying messages with embedded remote images, Zulip normally loads…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35962

Published Aug 29, 2022

Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticate…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 62 CVEsPage 1 of 3