VYPR

Zulip

by Zulip

Source repositories

CVEs (51)

  • CVE-2020-10857CriFeb 5, 2021
    risk 0.64cvss 9.8epss 0.03

    Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.

  • CVE-2020-12637CriMay 9, 2020
    risk 0.64cvss 9.8epss 0.01

    Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.

  • CVE-2021-3967HigFeb 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

  • CVE-2021-43799HigJan 25, 2022
    risk 0.56cvss 8.6epss 0.05

    Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which…

  • CVE-2022-35962HigAug 29, 2022
    risk 0.52cvss 8.0epss 0.01

    Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in…

  • CVE-2016-4427HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.

  • CVE-2026-25741HigFeb 26, 2026
    risk 0.46cvss 7.1epss 0.00

    Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe…

  • CVE-2023-32678MedAug 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete…

  • CVE-2021-43791MedDec 2, 2021
    risk 0.42cvss 6.5epss 0.01

    Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the confirmation objects associated with email invitations were not enforced properly in the new account registration flow. A…

  • CVE-2017-0896MedJun 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured…

  • CVE-2020-24582MedSep 10, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.

  • CVE-2020-9443MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82.

  • CVE-2018-9990MedApr 18, 2018
    risk 0.40cvss 6.1epss 0.01

    In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead.

  • CVE-2018-9987MedApr 18, 2018
    risk 0.40cvss 6.1epss 0.01

    In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications.

  • CVE-2018-9986MedApr 18, 2018
    risk 0.40cvss 6.1epss 0.01

    In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.

  • CVE-2026-40300MedMay 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege users to recover text that was edited away from other users'…

  • CVE-2021-3866MedJan 20, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.

  • CVE-2020-10858MedFeb 5, 2021
    risk 0.35cvss 5.3epss 0.01

    Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.

  • CVE-2018-9999MedApr 18, 2018
    risk 0.35cvss 5.4epss 0.01

    In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend.

  • CVE-2026-26058MedApr 3, 2026
    risk 0.33cvss 6.1epss 0.00

    Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to copy any file the zulip user…

Page 1 of 3