Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zulip Server MEDIUM 6.5
CVE-2026-40300

Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/his…

No fix yet
Fix from $1,600 2026-05-12
Zulip MEDIUM 6.1
CVE-2026-26058

Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server …

Fix: after 11.5
Fix from $1,600 2026-04-03
Zulip MEDIUM 5.3
CVE-2026-25742

Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before…

Fix: 11.6+
Fix from $1,600 2026-04-03
Zulip Server MEDIUM 5.4
CVE-2026-24050

Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored …

Fix: 11.5+
Fix from $1,600 2026-02-06
Zulip Server MEDIUM 5.4
CVE-2025-52559

Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview o…

Fix: 10.4+
Fix from $1,600 2025-07-02
Zulip MEDIUM 5.3
CVE-2025-47930

Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access contro…

Fix: 10.3+
Fix from $1,600 2025-05-16
Zulip Server HIGH 8.2
CVE-2025-31478

Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticat…

Fix: 10.2+
Fix from $1,950 2025-04-16
Zulip Server MEDIUM 5.3
CVE-2024-56136

Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an informat…

Fix: 9.4+
Fix from $1,600 2025-01-16
Zulip Server HIGH 7.5
CVE-2024-36612

Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.

Fix: after 8.3
Fix from $1,950 2024-11-29
Zulip MEDIUM 5.4
CVE-2024-36624

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.

Patch available
Fix from $1,600 2024-11-29
Zulip MEDIUM 5.4
CVE-2024-36625

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

Patch available
Fix from $1,600 2024-11-29
Zulip Server MEDIUM 6.5
CVE-2024-27286

Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only…

Fix: 8.3+
Fix from $1,600 2024-03-20
Zulip Server MEDIUM 6.5
CVE-2023-32678

Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private…

Fix: 7.3+
Fix from $1,600 2023-08-25
Zulip Server MEDIUM 6.1
CVE-2023-33186

Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work produc…

Patch available
Fix from $1,600 2023-05-30
Zulip MEDIUM 5.7
CVE-2022-35962

Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a m…

Fix: 27.190+
Fix from $1,600 2022-08-29
Zulip HIGH 7.5
CVE-2016-4427

In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.

Fix: 1.3.12+
Fix from $1,950 2022-07-28
Zulip HIGH 8.8
CVE-2022-31168

Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could cr…

Fix: 5.5+
Fix from $1,950 2022-07-22
Zulip HIGH 7.4
CVE-2022-24751

Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during a…

Fix: 4.11+
Fix from $1,950 2022-03-16
Zulip Server MEDIUM 5.4
CVE-2022-23656

Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting…

Fix: 2022-03-01+
Fix from $1,600 2022-03-02
Zulip HIGH 8.8
CVE-2021-3967

Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

Fix: 4.10+
Fix from $1,950 2022-02-26
Zulip Server CRITICAL 9.8
CVE-2022-21706

Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient acces…

Fix: 4.10.0+
Fix from $2,300 2022-02-26
Zulip CRITICAL 9.8
CVE-2021-43799EPSS 5%

Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.…

Fix: 4.9+
Fix from $2,300 2022-01-25
Zulip MEDIUM 5.4
CVE-2021-3866

Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3e…

Fix: after 4.8
Fix from $1,600 2022-01-20
Zulip MEDIUM 5.3
CVE-2021-43791

Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the…

Fix: 4.8+
Fix from $1,600 2021-12-02
Zulip MEDIUM 6.5
CVE-2021-41115

Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that au…

Fix: 4.7+
Fix from $1,600 2021-10-07
Zulip Server MEDIUM 5.3
CVE-2021-30479

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being a…

Fix: 3.4+
Fix from $1,600 2021-04-15
Zulip Desktop CRITICAL 9.8
CVE-2020-10857

Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.

Fix: 5.0.0+
Fix from $2,300 2021-02-05
Zulip Desktop MEDIUM 5.3
CVE-2020-10858

Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.

Fix: 5.0.0+
Fix from $1,600 2021-02-05
Zulip Server HIGH 8.8
CVE-2020-15070

Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write…

Fix: 2.1.7+
Fix from $1,950 2020-08-21
Zulip Server HIGH 7.5
CVE-2020-14215

Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.

Fix: 2.1.5+
Fix from $1,950 2020-08-21