Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-40300 Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/his… Zulip Server No fix yet Fix from $1,6002026-05-12 MEDIUM 6.1 CVE-2026-26058 Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server … Zulip after 11.5 Fix from $1,6002026-04-03 MEDIUM 5.3 CVE-2026-25742 Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before… Zulip 11.6+ Fix from $1,6002026-04-03 MEDIUM 5.4 CVE-2026-24050 Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored … Zulip Server 11.5+ Fix from $1,6002026-02-06 MEDIUM 5.4 CVE-2025-52559 Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview o… Zulip Server 10.4+ Fix from $1,6002025-07-02 MEDIUM 5.3 CVE-2025-47930 Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access contro… Zulip 10.3+ Fix from $1,6002025-05-16 HIGH 8.2 CVE-2025-31478 Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticat… Zulip Server 10.2+ Fix from $1,9502025-04-16 MEDIUM 5.3 CVE-2024-56136 Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an informat… Zulip Server 9.4+ Fix from $1,6002025-01-16 HIGH 7.5 CVE-2024-36612 Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers. Zulip Server after 8.3 Fix from $1,9502024-11-29 MEDIUM 5.4 CVE-2024-36624 Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js. Zulip Patch available Fix from $1,6002024-11-29 MEDIUM 5.4 CVE-2024-36625 Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts. Zulip Patch available Fix from $1,6002024-11-29 MEDIUM 6.5 CVE-2024-27286 Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only… Zulip Server 8.3+ Fix from $1,6002024-03-20 MEDIUM 6.5 CVE-2023-32678 Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private… Zulip Server 7.3+ Fix from $1,6002023-08-25 MEDIUM 6.1 CVE-2023-33186 Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work produc… Zulip Server Patch available Fix from $1,6002023-05-30 MEDIUM 5.7 CVE-2022-35962 Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a m… Zulip 27.190+ Fix from $1,6002022-08-29 HIGH 7.5 CVE-2016-4427 In zulip before 1.3.12, deactivated users could access messages if SSO was enabled. Zulip 1.3.12+ Fix from $1,9502022-07-28 HIGH 8.8 CVE-2022-31168 Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could cr… Zulip 5.5+ Fix from $1,9502022-07-22 HIGH 7.4 CVE-2022-24751 Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during a… Zulip 4.11+ Fix from $1,9502022-03-16 MEDIUM 5.4 CVE-2022-23656 Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting… Zulip Server 2022-03-01+ Fix from $1,6002022-03-02 HIGH 8.8 CVE-2021-3967 Improper Access Control in GitHub repository zulip/zulip prior to 4.10. Zulip 4.10+ Fix from $1,9502022-02-26 CRITICAL 9.8 CVE-2022-21706 Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient acces… Zulip Server 4.10.0+ Fix from $2,3002022-02-26 CRITICAL 9.8 CVE-2021-43799EPSS 5% Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.… Zulip 4.9+ Fix from $2,3002022-01-25 MEDIUM 5.4 CVE-2021-3866 Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3e… Zulip after 4.8 Fix from $1,6002022-01-20 MEDIUM 5.3 CVE-2021-43791 Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the… Zulip 4.8+ Fix from $1,6002021-12-02 MEDIUM 6.5 CVE-2021-41115 Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that au… Zulip 4.7+ Fix from $1,6002021-10-07 MEDIUM 5.3 CVE-2021-30479 An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being a… Zulip Server 3.4+ Fix from $1,6002021-04-15 CRITICAL 9.8 CVE-2020-10857 Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution. Zulip Desktop 5.0.0+ Fix from $2,3002021-02-05 MEDIUM 5.3 CVE-2020-10858 Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler. Zulip Desktop 5.0.0+ Fix from $1,6002021-02-05 HIGH 8.8 CVE-2020-15070 Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write… Zulip Server 2.1.7+ Fix from $1,9502020-08-21 HIGH 7.5 CVE-2020-14215 Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations. Zulip Server 2.1.5+ Fix from $1,9502020-08-21