Zulip
by Zulip
Source repositories
CVEs (51)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10857 | Cri | 0.64 | 9.8 | 0.03 | Feb 5, 2021 | Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution. | ||
| CVE-2020-12637 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2020 | Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option. | ||
| CVE-2021-3967 | Hig | 0.57 | 8.8 | 0.01 | Feb 26, 2022 | Improper Access Control in GitHub repository zulip/zulip prior to 4.10. | ||
| CVE-2021-43799 | Hig | 0.56 | 8.6 | 0.05 | Jan 25, 2022 | Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which… | ||
| CVE-2022-35962 | Hig | 0.52 | 8.0 | 0.01 | Aug 29, 2022 | Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in… | ||
| CVE-2016-4427 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | In zulip before 1.3.12, deactivated users could access messages if SSO was enabled. | ||
| CVE-2026-25741 | Hig | 0.46 | 7.1 | 0.00 | Feb 26, 2026 | Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe… | ||
| CVE-2023-32678 | Med | 0.42 | 6.5 | 0.00 | Aug 25, 2023 | Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete… | ||
| CVE-2021-43791 | Med | 0.42 | 6.5 | 0.01 | Dec 2, 2021 | Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the confirmation objects associated with email invitations were not enforced properly in the new account registration flow. A… | ||
| CVE-2017-0896 | Med | 0.42 | 6.5 | 0.01 | Jun 2, 2017 | Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured… | ||
| CVE-2020-24582 | Med | 0.40 | 6.1 | 0.01 | Sep 10, 2020 | Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface. | ||
| CVE-2020-9443 | Med | 0.40 | 6.1 | 0.01 | Mar 18, 2020 | Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82. | ||
| CVE-2018-9990 | Med | 0.40 | 6.1 | 0.01 | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead. | ||
| CVE-2018-9987 | Med | 0.40 | 6.1 | 0.01 | Apr 18, 2018 | In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications. | ||
| CVE-2018-9986 | Med | 0.40 | 6.1 | 0.01 | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor. | ||
| CVE-2026-40300 | Med | 0.35 | 6.5 | 0.00 | May 12, 2026 | Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege users to recover text that was edited away from other users'… | ||
| CVE-2021-3866 | Med | 0.35 | 5.4 | 0.01 | Jan 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6. | ||
| CVE-2020-10858 | Med | 0.35 | 5.3 | 0.01 | Feb 5, 2021 | Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler. | ||
| CVE-2018-9999 | Med | 0.35 | 5.4 | 0.01 | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend. | ||
| CVE-2026-26058 | Med | 0.33 | 6.1 | 0.00 | Apr 3, 2026 | Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to copy any file the zulip user… |
- risk 0.64cvss 9.8epss 0.03
Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.
- risk 0.64cvss 9.8epss 0.01
Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.
- risk 0.57cvss 8.8epss 0.01
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
- risk 0.56cvss 8.6epss 0.05
Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which…
- risk 0.52cvss 8.0epss 0.01
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in…
- risk 0.49cvss 7.5epss 0.01
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
- risk 0.46cvss 7.1epss 0.00
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe…
- risk 0.42cvss 6.5epss 0.00
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete…
- risk 0.42cvss 6.5epss 0.01
Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the confirmation objects associated with email invitations were not enforced properly in the new account registration flow. A…
- risk 0.42cvss 6.5epss 0.01
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured…
- risk 0.40cvss 6.1epss 0.01
Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.
- risk 0.40cvss 6.1epss 0.01
Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82.
- risk 0.40cvss 6.1epss 0.01
In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead.
- risk 0.40cvss 6.1epss 0.01
In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications.
- risk 0.40cvss 6.1epss 0.01
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
- risk 0.35cvss 6.5epss 0.00
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege users to recover text that was edited away from other users'…
- risk 0.35cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.
- risk 0.35cvss 5.3epss 0.01
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
- risk 0.35cvss 5.4epss 0.01
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend.
- risk 0.33cvss 6.1epss 0.00
Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to copy any file the zulip user…
Page 1 of 3