CVE-2026-26058
- EPSS 0.01%
- Veröffentlicht 03.04.2026 20:59:08
- Zuletzt bearbeitet 07.04.2026 13:20:55
Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to ...
CVE-2026-25742
- EPSS 0.04%
- Veröffentlicht 03.04.2026 20:12:07
- Zuletzt bearbeitet 13.04.2026 18:07:16
Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, even after spectator access (enable_spectator_access / WEB_PUBLIC_STREAMS_ENABLED) is ...
CVE-2026-25741
- EPSS 0.05%
- Veröffentlicht 26.02.2026 21:44:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. Wh...
CVE-2026-24050
- EPSS 0.01%
- Veröffentlicht 06.02.2026 18:20:33
- Zuletzt bearbeitet 23.02.2026 20:48:10
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly in...
CVE-2025-52559
- EPSS 0.06%
- Veröffentlicht 02.07.2025 19:31:12
- Zuletzt bearbeitet 02.10.2025 01:51:09
Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cros...
CVE-2025-47930
- EPSS 0.21%
- Veröffentlicht 15.05.2025 23:17:29
- Zuletzt bearbeitet 27.08.2025 02:26:59
Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the ch...
CVE-2025-31478
- EPSS 0.24%
- Veröffentlicht 16.04.2025 21:28:23
- Zuletzt bearbeitet 23.01.2026 17:16:06
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restrictions on em...
CVE-2025-30369
- EPSS 0.2%
- Veröffentlicht 31.03.2025 17:15:42
- Zuletzt bearbeitet 27.09.2025 00:15:46
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as...
CVE-2025-30368
- EPSS 0.23%
- Veröffentlicht 31.03.2025 17:15:42
- Zuletzt bearbeitet 27.08.2025 01:51:53
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. The...
CVE-2025-27149
- EPSS 0.24%
- Veröffentlicht 31.03.2025 16:15:23
- Zuletzt bearbeitet 27.09.2025 00:15:56
Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of user-agent types identifying specific in...