Zulip
by Zulip
Source repositories
CVEs (51)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-25742 | Med | 0.27 | 5.3 | 0.00 | Apr 3, 2026 | Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, even after spectator access (enable_spectator_access / WEB_PUBLIC_STREAMS_ENABLED) is disabled, attachments… | ||
| CVE-2025-25195 | Med | 0.21 | 4.3 | 0.00 | Feb 13, 2025 | Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) demotes channels to being "inactive" after they have not received traffic for 180 days. However, upon doing so, an event was sent to all users in the… | ||
| CVE-2025-30369 | Low | 0.18 | 2.7 | 0.00 | Mar 31, 2025 | Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an… | ||
| CVE-2025-27149 | Low | 0.18 | 2.7 | 0.00 | Mar 31, 2025 | Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of user-agent types identifying specific integrations or HTTP libraries… | ||
| CVE-2022-31017 | Low | 0.13 | 2.0 | 0.01 | Jun 25, 2022 | Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic error. A stream configured as private with protected history, where new subscribers should not be allowed to see messages sent before they were subscribed, when… | ||
| CVE-2026-24050 | Med | 0.00 | 5.4 | 0.00 | Feb 6, 2026 | Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the… | ||
| CVE-2025-52559 | Med | 0.00 | 6.8 | 0.00 | Jul 2, 2025 | Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS)… | ||
| CVE-2025-47930 | Med | 0.00 | 5.3 | 0.00 | May 16, 2025 | Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A… | ||
| CVE-2025-31478 | Hig | 0.00 | 8.2 | 0.00 | Apr 16, 2025 | Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restrictions on email address domains or… | ||
| CVE-2025-30368 | Low | 0.00 | 2.7 | 0.00 | Mar 31, 2025 | Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of… | ||
| CVE-2024-56136 | Med | 0.00 | 5.3 | 0.01 | Jan 16, 2025 | Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is hosting multiple organizations, an unauthenticated user can make a request and… | ||
| CVE-2024-36612 | Hig | 0.00 | 7.5 | 0.01 | Nov 29, 2024 | Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers. | ||
| CVE-2024-36624 | Med | 0.00 | 5.4 | 0.00 | Nov 29, 2024 | Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js. | ||
| CVE-2024-36625 | Med | 0.00 | 5.4 | 0.00 | Nov 29, 2024 | Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts. | ||
| CVE-2024-27286 | Med | 0.00 | 6.5 | 0.01 | Mar 20, 2024 | Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well, or move just a single message. If the user chose to just move one message, and was moving it from a… | ||
| CVE-2024-21630 | Med | 0.00 | 4.3 | 0.00 | Jan 25, 2024 | Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be… | ||
| CVE-2023-47642 | Med | 0.00 | 4.3 | 0.00 | Nov 16, 2023 | Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream. As a result, users who had… | ||
| CVE-2023-33186 | Hig | 0.00 | 8.2 | 0.01 | May 30, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, including beta versions 7.0-beta1 and… | ||
| CVE-2023-28623 | Med | 0.00 | 6.5 | 0.01 | May 19, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBackend` and `EmailAuthBackend`) are the only ones enabled in… | ||
| CVE-2023-32677 | Low | 0.00 | 3.1 | 0.01 | May 19, 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invite users to the organization. In Zulip Server 6.1 and below, the UI which allows… |
- risk 0.27cvss 5.3epss 0.00
Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, even after spectator access (enable_spectator_access / WEB_PUBLIC_STREAMS_ENABLED) is disabled, attachments…
- risk 0.21cvss 4.3epss 0.00
Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) demotes channels to being "inactive" after they have not received traffic for 180 days. However, upon doing so, an event was sent to all users in the…
- risk 0.18cvss 2.7epss 0.00
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an…
- risk 0.18cvss 2.7epss 0.00
Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of user-agent types identifying specific integrations or HTTP libraries…
- risk 0.13cvss 2.0epss 0.01
Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic error. A stream configured as private with protected history, where new subscribers should not be allowed to see messages sent before they were subscribed, when…
- risk 0.00cvss 5.4epss 0.00
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the…
- risk 0.00cvss 6.8epss 0.00
Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS)…
- risk 0.00cvss 5.3epss 0.00
Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A…
- risk 0.00cvss 8.2epss 0.00
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restrictions on email address domains or…
- risk 0.00cvss 2.7epss 0.00
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of…
- risk 0.00cvss 5.3epss 0.01
Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is hosting multiple organizations, an unauthenticated user can make a request and…
- risk 0.00cvss 7.5epss 0.01
Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
- risk 0.00cvss 5.4epss 0.00
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.
- risk 0.00cvss 5.4epss 0.00
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.
- risk 0.00cvss 6.5epss 0.01
Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well, or move just a single message. If the user chose to just move one message, and was moving it from a…
- risk 0.00cvss 4.3epss 0.00
Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be…
- risk 0.00cvss 4.3epss 0.00
Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream. As a result, users who had…
- risk 0.00cvss 8.2epss 0.01
Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, including beta versions 7.0-beta1 and…
- risk 0.00cvss 6.5epss 0.01
Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBackend` and `EmailAuthBackend`) are the only ones enabled in…
- risk 0.00cvss 3.1epss 0.01
Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invite users to the organization. In Zulip Server 6.1 and below, the UI which allows…
Page 2 of 3