Zulip
by Zulip
Source repositories
CVEs (51)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10857 | Cri | 0.64 | 9.8 | 0.03 | Feb 5, 2021 | Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution. | ||
| CVE-2020-12637 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2020 | Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option. | ||
| CVE-2022-35962 | Hig | 0.52 | 8.0 | 0.01 | Aug 29, 2022 | Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in… | ||
| CVE-2016-4427 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | In zulip before 1.3.12, deactivated users could access messages if SSO was enabled. | ||
| CVE-2026-25741 | Hig | 0.46 | 7.1 | 0.00 | Feb 26, 2026 | Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe… | ||
| CVE-2023-32678 | Med | 0.42 | 6.5 | 0.00 | Aug 25, 2023 | Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete… | ||
| CVE-2017-0896 | Med | 0.42 | 6.5 | 0.01 | Jun 2, 2017 | Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured… | ||
| CVE-2020-24582 | Med | 0.40 | 6.1 | 0.01 | Sep 10, 2020 | Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface. | ||
| CVE-2020-9443 | Med | 0.40 | 6.1 | 0.01 | Mar 18, 2020 | Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82. | ||
| CVE-2018-9990 | Med | 0.40 | 6.1 | 0.01 | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead. | ||
| CVE-2018-9987 | Med | 0.40 | 6.1 | 0.01 | Apr 18, 2018 | In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications. | ||
| CVE-2018-9986 | Med | 0.40 | 6.1 | 0.01 | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor. | ||
| CVE-2026-40300 | Med | 0.35 | 6.5 | 0.00 | May 12, 2026 | Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege users to recover text that was edited away from other users'… | ||
| CVE-2020-10858 | Med | 0.35 | 5.3 | 0.01 | Feb 5, 2021 | Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler. | ||
| CVE-2018-9999 | Med | 0.35 | 5.4 | 0.01 | Apr 18, 2018 | In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend. | ||
| CVE-2026-26058 | Med | 0.33 | 6.1 | 0.00 | Apr 3, 2026 | Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to copy any file the zulip user… | ||
| CVE-2022-31134 | Med | 0.32 | 4.9 | 0.01 | Jul 12, 2022 | Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data" export. While this export is only accessible to… | ||
| CVE-2022-36048 | Med | 0.28 | 4.3 | 0.01 | Aug 31, 2022 | Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying messages with embedded remote images, Zulip normally loads the image preview via a go-camo proxy server. However, an attacker who can send messages could… | ||
| CVE-2016-4426 | Med | 0.28 | 4.3 | 0.01 | Jul 28, 2022 | In zulip before 1.3.12, bot API keys were accessible to other users in the same realm. | ||
| CVE-2017-0881 | Med | 0.28 | 4.3 | 0.01 | Mar 28, 2017 | An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to… |
- risk 0.64cvss 9.8epss 0.03
Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.
- risk 0.64cvss 9.8epss 0.01
Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.
- risk 0.52cvss 8.0epss 0.01
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in…
- risk 0.49cvss 7.5epss 0.01
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
- risk 0.46cvss 7.1epss 0.00
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe…
- risk 0.42cvss 6.5epss 0.00
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete…
- risk 0.42cvss 6.5epss 0.01
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured…
- risk 0.40cvss 6.1epss 0.01
Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.
- risk 0.40cvss 6.1epss 0.01
Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82.
- risk 0.40cvss 6.1epss 0.01
In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead.
- risk 0.40cvss 6.1epss 0.01
In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications.
- risk 0.40cvss 6.1epss 0.01
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
- risk 0.35cvss 6.5epss 0.00
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege users to recover text that was edited away from other users'…
- risk 0.35cvss 5.3epss 0.01
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
- risk 0.35cvss 5.4epss 0.01
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend.
- risk 0.33cvss 6.1epss 0.00
Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to copy any file the zulip user…
- risk 0.32cvss 4.9epss 0.01
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data" export. While this export is only accessible to…
- risk 0.28cvss 4.3epss 0.01
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying messages with embedded remote images, Zulip normally loads the image preview via a go-camo proxy server. However, an attacker who can send messages could…
- risk 0.28cvss 4.3epss 0.01
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.
- risk 0.28cvss 4.3epss 0.01
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to…
Page 1 of 3