VYPR

Zulip Server

by Zulip

Source repositories

CVEs (44)

  • CVE-2021-30477MedApr 15, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to…

  • CVE-2019-16216MedSep 18, 2019
    risk 0.28cvss 5.4epss 0.01

    Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attack on other logged-in users. On a Zulip server using the default local uploads…

  • CVE-2017-0881MedMar 28, 2017
    risk 0.28cvss 4.3epss 0.01

    An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to…

  • CVE-2025-30369LowMar 31, 2025
    risk 0.18cvss 2.7epss 0.00

    Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an…

  • CVE-2025-27149LowMar 31, 2025
    risk 0.18cvss 2.7epss 0.00

    Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of user-agent types identifying specific integrations or HTTP libraries…

  • CVE-2021-30487LowApr 15, 2021
    risk 0.18cvss 2.7epss 0.01

    In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.

  • CVE-2026-24050MedFeb 6, 2026
    risk 0.00cvss 5.4epss 0.00

    Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the…

  • CVE-2025-52559MedJul 2, 2025
    risk 0.00cvss 6.8epss 0.00

    Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cross-site scripting (XSS)…

  • CVE-2025-31478HigApr 16, 2025
    risk 0.00cvss 8.2epss 0.00

    Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restrictions on email address domains or…

  • CVE-2025-30368LowMar 31, 2025
    risk 0.00cvss 2.7epss 0.00

    Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. Therefore, an administrator of…

  • CVE-2024-56136MedJan 16, 2025
    risk 0.00cvss 5.3epss 0.01

    Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is hosting multiple organizations, an unauthenticated user can make a request and…

  • CVE-2024-36612HigNov 29, 2024
    risk 0.00cvss 7.5epss 0.01

    Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.

  • CVE-2024-27286MedMar 20, 2024
    risk 0.00cvss 6.5epss 0.01

    Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well, or move just a single message. If the user chose to just move one message, and was moving it from a…

  • CVE-2024-21630MedJan 25, 2024
    risk 0.00cvss 4.3epss 0.00

    Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be…

  • CVE-2023-47642MedNov 16, 2023
    risk 0.00cvss 4.3epss 0.00

    Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream. As a result, users who had…

  • CVE-2023-33186HigMay 30, 2023
    risk 0.00cvss 8.2epss 0.01

    Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, including beta versions 7.0-beta1 and…

  • CVE-2023-32677LowMay 19, 2023
    risk 0.00cvss 3.1epss 0.01

    Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invite users to the organization. In Zulip Server 6.1 and below, the UI which allows…

  • CVE-2023-22735MedFeb 7, 2023
    risk 0.00cvss 4.4epss 0.01

    Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68b` users could upload files with arbitrary `Content-Type` which would be served from the Zulip hostname with `Content-Disposition: inline` and no…

  • CVE-2022-41914LowNov 16, 2022
    risk 0.00cvss 3.7epss 0.01

    Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a comparator that did not run in constant time. Therefore, it…

  • CVE-2022-31168MedJul 22, 2022
    risk 0.00cvss 5.4epss 0.01

    Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server…