Skip to main content

Vendor/product archive

zulip / zulip_server CVEs

Beta · best-effort

40 CVEs tagged to zulip / zulip_server1 Critical, 7 High, 28 Medium, 4 Low, 0 Unrated.

CVE-2026-40300

Published May 12, 2026

Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24050

Published Feb 6, 2026

Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel…

CVSS 1.1 · Low
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-52559

Published Jul 2, 2025

Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-31478

Published Apr 16, 2025

Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authen…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-30369

Published Mar 31, 2025

Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its han…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27149

Published Mar 31, 2025

Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks p…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-56136

Published Jan 16, 2025

Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27286

Published Mar 20, 2024

Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21630

Published Jan 25, 2024

Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47642

Published Nov 16, 2023

Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly conti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32678

Published Aug 25, 2023

Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33186

Published May 30, 2023

Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22735

Published Feb 7, 2023

Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68b` users could upload files with arbitrary `Content-Type` w…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41914

Published Nov 16, 2022

Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-31134

Published Jul 12, 2022

Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which pr…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23656

Published Mar 2, 2022

Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting vulnerability on the recent t…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21706

Published Feb 26, 2022

Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invit…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30487

Published Apr 15, 2021

In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installat…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-30479

Published Apr 15, 2021

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30478

Published Apr 15, 2021

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30477

Published Apr 15, 2021

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15070

Published Aug 21, 2020

Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile fiel…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14215

Published Aug 21, 2020

Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2