« Volver al listado

Zulip

Zulip Server: vulnerabilidades y CVE

Zulip Server tiene 40 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE40
Últimos 12 meses2
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-40300Media (6)0.35%—12 may 2026
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege…
CVE-2026-24050Baja (1.1)0.24%—6 feb 2026
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities…
CVE-2025-52559Media (5.4)0.28%—2 jul 2025
Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the…
CVE-2025-31478Alta (8.2)0.36%—16 abr 2025
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the…
CVE-2025-30369Baja (2.7)0.27%—31 mar 2025
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field…
CVE-2025-27149Media (4.6)0.30%—31 mar 2025
Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of…
CVE-2024-56136Media (6.9)0.57%—16 ene 2025
Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is hosting multiple…
CVE-2024-36612Alta (7.5)0.59%—29 nov 2024
Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
CVE-2024-27286Media (6.5)0.52%—20 mar 2024
Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well, or move just a single message. If the…
CVE-2024-21630Media (4.3)0.37%—25 ene 2024
Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it…
CVE-2023-47642Media (4.3)0.48%—16 nov 2023
Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to…
CVE-2023-32678Media (6.5)0.48%—25 ago 2023
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit…
CVE-2023-33186Media (6.1)0.62%—30 may 2023
Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from…
CVE-2023-22735Media (4.6)0.52%—7 feb 2023
Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68b` users could upload files with arbitrary `Content-Type` which would be served from the Zulip…
CVE-2022-41914Baja (3.7)0.55%—16 nov 2022
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a…
CVE-2022-31134Media (4.9)0.92%—12 jul 2022
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data"…
CVE-2022-23656Media (5.4)0.58%—2 mar 2022
Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting vulnerability on the recent topics page. An attacker could…
CVE-2022-21706Crítica (9.8)1.2%—26 feb 2022
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which…
CVE-2021-30487Baja (2.7)0.65%—15 abr 2021
In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.
CVE-2021-30479Media (5.3)0.86%—15 abr 2021
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been…
CVE-2021-30478Media (4.3)0.57%—15 abr 2021
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages…
CVE-2021-30477Media (4.3)0.66%—15 abr 2021
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to…
CVE-2020-15070Alta (8.8)1.2%—21 ago 2020
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
CVE-2020-14215Alta (7.5)0.89%—21 ago 2020
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
CVE-2020-14194Media (5.4)0.69%—21 ago 2020
Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.
CVE-2020-12759Media (6.1)0.67%—21 ago 2020
Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.
CVE-2020-9445Media (6.1)0.67%—20 abr 2020
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
CVE-2020-9444Media (6.1)0.67%—20 abr 2020
Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality.
CVE-2020-10935Media (5.4)0.72%—20 abr 2020
Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
CVE-2019-19775Media (6.1)0.86%—18 dic 2019
The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1078.001 Default Accounts1
  3. T1499 Endpoint Denial of Service1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Zulip