VYPR
Vendor

Zulip

Products
3
CVEs
67
Across products
98
Status
Private

Products

3

Recent CVEs

67
View all 67 CVEs →
  • CVE-2020-10857CriFeb 5, 2021
    risk 0.64cvss 9.8epss 0.03

    Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.

  • CVE-2020-12637CriMay 9, 2020
    risk 0.64cvss 9.8epss 0.01

    Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.

  • CVE-2021-3967HigFeb 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

  • CVE-2020-15070HigAug 21, 2020
    risk 0.57cvss 8.8epss 0.01

    Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.

  • CVE-2019-18933CriNov 21, 2019
    risk 0.57cvss 9.8epss 0.01

    In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal…

  • CVE-2017-0910HigNov 27, 2017
    risk 0.57cvss 8.8epss 0.01

    In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.

  • CVE-2021-43799HigJan 25, 2022
    risk 0.56cvss 8.6epss 0.05

    Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which…

  • CVE-2022-35962HigAug 29, 2022
    risk 0.52cvss 8.0epss 0.01

    Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. A patch was released in…

  • CVE-2016-4427HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.

  • CVE-2020-14215HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.

  • CVE-2026-25741HigFeb 26, 2026
    risk 0.46cvss 7.1epss 0.00

    Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe…

  • CVE-2023-32678MedAug 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete…

  • CVE-2021-43791MedDec 2, 2021
    risk 0.42cvss 6.5epss 0.01

    Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the confirmation objects associated with email invitations were not enforced properly in the new account registration flow. A…

  • CVE-2017-0896MedJun 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured…

  • CVE-2020-24582MedSep 10, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.

  • CVE-2020-12759MedAug 21, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.

  • CVE-2020-9445MedApr 20, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.

  • CVE-2020-9444MedApr 20, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.

  • CVE-2020-9443MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82.

  • CVE-2019-19775MedDec 18, 2019
    risk 0.40cvss 6.1epss 0.01

    The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.

VYPR — Vulnerability Intelligence