Zulip
62 known vulnerabilities
Top Products
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "move
Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arb
Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool.
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profil
Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL
Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create p
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed t
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricte
Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data exp
Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above
Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.
Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all mes
Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applie
Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who h
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used
Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and ch
Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBa
Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zu
Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a membe
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessibl
Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic erro
Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable
Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnera
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vul
Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In version
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6
Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected ver
Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to c
In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to stream
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature re
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (prev
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permissi
Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remo
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrato
Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
Frequently Asked Questions
How many CVEs affect Zulip?
Zulip has 62 CVE records in our database, including 2 critical and 11 high severity vulnerabilities.
What are the most severe Zulip vulnerabilities?
Zulip has 2 critical severity (CVSS 9.0+) and 11 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Zulip vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Zulip products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Zulip Vulnerabilities
CyberStrike scans your infrastructure for Zulip vulnerabilities and provides real-time remediation guidance.
Get Started