CVE-2025-52559
- EPSS 0.05%
- Veröffentlicht 02.07.2025 19:31:12
- Zuletzt bearbeitet 02.10.2025 01:51:09
Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cros...
CVE-2025-31478
- EPSS 0.05%
- Veröffentlicht 16.04.2025 21:28:23
- Zuletzt bearbeitet 27.09.2025 00:10:58
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restrictions on em...
CVE-2025-30369
- EPSS 0.03%
- Veröffentlicht 31.03.2025 17:15:42
- Zuletzt bearbeitet 27.09.2025 00:15:46
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as...
CVE-2025-27149
- EPSS 0.03%
- Veröffentlicht 31.03.2025 16:15:23
- Zuletzt bearbeitet 27.09.2025 00:15:56
Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of user-agent types identifying specific in...
CVE-2024-56136
- EPSS 0.1%
- Veröffentlicht 16.01.2025 20:15:33
- Zuletzt bearbeitet 27.09.2025 00:16:08
Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is hosting multiple organizations, an unauthenticated u...
CVE-2024-36612
- EPSS 0.22%
- Veröffentlicht 29.11.2024 20:15:20
- Zuletzt bearbeitet 09.04.2025 18:54:42
Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
CVE-2024-27286
- EPSS 0.06%
- Veröffentlicht 20.03.2024 20:15:08
- Zuletzt bearbeitet 03.09.2025 14:30:33
Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well, or move just a single message. If the user chose to just move one mess...
CVE-2024-21630
- EPSS 0.11%
- Veröffentlicht 25.01.2024 20:15:40
- Zuletzt bearbeitet 21.11.2024 08:54:45
Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation ha...
CVE-2023-47642
- EPSS 0.38%
- Veröffentlicht 16.11.2023 22:15:28
- Zuletzt bearbeitet 21.11.2024 08:30:35
Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream...
CVE-2023-32678
- EPSS 0.03%
- Veröffentlicht 25.08.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:03:50
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages...