Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Zulip

62 known vulnerabilities

2
CRITICAL
11
HIGH
42
MEDIUM
7
LOW

Top Products

zulip server 40 zulip 20 zulip desktop 2
62 CVEs · Page 2/2
5.4
CVE-2020-10935

Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.

6.1
CVE-2019-19775

The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible

9.8
CVE-2019-18933

In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registere

5.4
CVE-2019-16216

Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server

6.5
CVE-2019-16215

The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A use

5.4
CVE-2018-9999

In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR stor

6.1
CVE-2018-9990

In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead.

6.1
CVE-2018-9987

In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications.

6.1
CVE-2018-9986

In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.

8.8
CVE-2017-0910

In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authori

6.5
CVE-2017-0896

Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zuli

4.3
CVE-2017-0881

An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat appl

Frequently Asked Questions

How many CVEs affect Zulip?

Zulip has 62 CVE records in our database, including 2 critical and 11 high severity vulnerabilities.

What are the most severe Zulip vulnerabilities?

Zulip has 2 critical severity (CVSS 9.0+) and 11 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Zulip vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Zulip products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Zulip Vulnerabilities

CyberStrike scans your infrastructure for Zulip vulnerabilities and provides real-time remediation guidance.

Get Started