Zulip
Zulip Server: vulnerabilidades y CVE
Zulip Server tiene 40 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40300 | Media (6) | 0.35% | — | 12 may 2026 | Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allowing low-privilege… |
| CVE-2026-24050 | Baja (1.1) | 0.24% | — | 6 feb 2026 | Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities… |
| CVE-2025-52559 | Media (5.4) | 0.28% | — | 2 jul 2025 | Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the… |
| CVE-2025-31478 | Alta (8.2) | 0.36% | — | 16 abr 2025 | Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the… |
| CVE-2025-30369 | Baja (2.7) | 0.27% | — | 31 mar 2025 | Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field… |
| CVE-2025-27149 | Media (4.6) | 0.30% | — | 31 mar 2025 | Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of… |
| CVE-2024-56136 | Media (6.9) | 0.57% | — | 16 ene 2025 | Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is hosting multiple… |
| CVE-2024-36612 | Alta (7.5) | 0.59% | — | 29 nov 2024 | Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers. |
| CVE-2024-27286 | Media (6.5) | 0.52% | — | 20 mar 2024 | Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well, or move just a single message. If the… |
| CVE-2024-21630 | Media (4.3) | 0.37% | — | 25 ene 2024 | Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it… |
| CVE-2023-47642 | Media (4.3) | 0.48% | — | 16 nov 2023 | Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to… |
| CVE-2023-32678 | Media (6.5) | 0.48% | — | 25 ago 2023 | Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit… |
| CVE-2023-33186 | Media (6.1) | 0.62% | — | 30 may 2023 | Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from… |
| CVE-2023-22735 | Media (4.6) | 0.52% | — | 7 feb 2023 | Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68b` users could upload files with arbitrary `Content-Type` which would be served from the Zulip… |
| CVE-2022-41914 | Baja (3.7) | 0.55% | — | 16 nov 2022 | Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a… |
| CVE-2022-31134 | Media (4.9) | 0.92% | — | 12 jul 2022 | Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data"… |
| CVE-2022-23656 | Media (5.4) | 0.58% | — | 2 mar 2022 | Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnerable to a cross-site scripting vulnerability on the recent topics page. An attacker could… |
| CVE-2022-21706 | Crítica (9.8) | 1.2% | — | 26 feb 2022 | Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which… |
| CVE-2021-30487 | Baja (2.7) | 0.65% | — | 15 abr 2021 | In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation. |
| CVE-2021-30479 | Media (5.3) | 0.86% | — | 15 abr 2021 | An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been… |
| CVE-2021-30478 | Media (4.3) | 0.57% | — | 15 abr 2021 | An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages… |
| CVE-2021-30477 | Media (4.3) | 0.66% | — | 15 abr 2021 | An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to… |
| CVE-2020-15070 | Alta (8.8) | 1.2% | — | 21 ago 2020 | Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value. |
| CVE-2020-14215 | Alta (7.5) | 0.89% | — | 21 ago 2020 | Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations. |
| CVE-2020-14194 | Media (5.4) | 0.69% | — | 21 ago 2020 | Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link. |
| CVE-2020-12759 | Media (6.1) | 0.67% | — | 21 ago 2020 | Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook. |
| CVE-2020-9445 | Media (6.1) | 0.67% | — | 20 abr 2020 | Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality. |
| CVE-2020-9444 | Media (6.1) | 0.67% | — | 20 abr 2020 | Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality. |
| CVE-2020-10935 | Media (5.4) | 0.72% | — | 20 abr 2020 | Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover. |
| CVE-2019-19775 | Media (6.1) | 0.86% | — | 18 dic 2019 | The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.