Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Zulip

62 known vulnerabilities

2
CRITICAL
11
HIGH
42
MEDIUM
7
LOW

Top Products

zulip server 40 zulip 20 zulip desktop 2
62 CVEs · Page 1/2
6.5
CVE-2026-40300

Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "move

6.1
CVE-2026-26058

Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arb

5.3
CVE-2026-25742

Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool.

5.4
CVE-2026-24050

Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profil

6.8
CVE-2025-52559

Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL

5.3
CVE-2025-47930

Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create p

8.2
CVE-2025-31478

Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely

2.7
CVE-2025-30369

Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed t

2.7
CVE-2025-30368

Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricte

2.7
CVE-2025-27149

Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data exp

5.3
CVE-2024-56136

Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above

7.5
CVE-2024-36612

Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.

5.4
CVE-2024-36624

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.

5.4
CVE-2024-36625

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

6.5
CVE-2024-27286

Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all mes

4.3
CVE-2024-21630

Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applie

4.3
CVE-2023-47642

Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who h

6.5
CVE-2023-32678

Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used

8.2
CVE-2023-33186

Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and ch

6.5
CVE-2023-28623

Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBa

3.1
CVE-2023-32677

Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zu

4.4
CVE-2023-22735

Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68

3.7
CVE-2022-41914

Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM

4.3
CVE-2022-36048

Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying

8.0
CVE-2022-35962

Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version

7.5
CVE-2016-4427

In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.

4.3
CVE-2016-4426

In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.

5.4
CVE-2022-31168

Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a membe

4.9
CVE-2022-31134

Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessibl

2.0
CVE-2022-31017

Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic erro

5.4
CVE-2022-24751

Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable

4.6
CVE-2022-23656

Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnera

8.8
CVE-2021-3967

Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

7.2
CVE-2022-21706

Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vul

8.6
CVE-2021-43799

Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In version

5.4
CVE-2021-3866

Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6

6.5
CVE-2021-43791

Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected ver

4.3
CVE-2021-41115

Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to c

2.7
CVE-2021-30487

In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to stream

5.3
CVE-2021-30479

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature re

4.3
CVE-2021-30478

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (prev

4.3
CVE-2021-30477

An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing

5.3
CVE-2020-10858

Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permissi

9.8
CVE-2020-10857

Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remo

8.8
CVE-2020-15070

Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres

7.5
CVE-2020-14215

Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrato

5.4
CVE-2020-14194

Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.

6.1
CVE-2020-12759

Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.

6.1
CVE-2020-9445

Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.

6.1
CVE-2020-9444

Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.

Frequently Asked Questions

How many CVEs affect Zulip?

Zulip has 62 CVE records in our database, including 2 critical and 11 high severity vulnerabilities.

What are the most severe Zulip vulnerabilities?

Zulip has 2 critical severity (CVSS 9.0+) and 11 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Zulip vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Zulip products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Zulip Vulnerabilities

CyberStrike scans your infrastructure for Zulip vulnerabilities and provides real-time remediation guidance.

Get Started