CVE-2026-25741
- EPSS 0.04%
- Veröffentlicht 26.02.2026 21:44:34
- Zuletzt bearbeitet 27.02.2026 14:06:37
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. Wh...
CVE-2026-24050
- EPSS 0.01%
- Veröffentlicht 06.02.2026 18:20:33
- Zuletzt bearbeitet 23.02.2026 20:48:10
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly in...
CVE-2025-52559
- EPSS 0.03%
- Veröffentlicht 02.07.2025 19:31:12
- Zuletzt bearbeitet 02.10.2025 01:51:09
Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL of a server shows a preview of what the email weekly digest would contain. This URL, though not the digest itself, contains a cros...
CVE-2025-47930
- EPSS 0.07%
- Veröffentlicht 15.05.2025 23:17:29
- Zuletzt bearbeitet 27.08.2025 02:26:59
Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the ch...
CVE-2025-31478
- EPSS 0.24%
- Veröffentlicht 16.04.2025 21:28:23
- Zuletzt bearbeitet 23.01.2026 17:16:06
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restrictions on em...
CVE-2025-30369
- EPSS 0.2%
- Veröffentlicht 31.03.2025 17:15:42
- Zuletzt bearbeitet 27.09.2025 00:15:46
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as...
CVE-2025-30368
- EPSS 0.23%
- Veröffentlicht 31.03.2025 17:15:42
- Zuletzt bearbeitet 27.08.2025 01:51:53
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field belongs to the same organization as the user. The...
CVE-2025-27149
- EPSS 0.24%
- Veröffentlicht 31.03.2025 16:15:23
- Zuletzt bearbeitet 27.09.2025 00:15:56
Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks private data. The collection of user-agent types identifying specific in...
CVE-2025-25195
- EPSS 0.16%
- Veröffentlicht 13.02.2025 22:15:13
- Zuletzt bearbeitet 13.02.2025 22:15:13
Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) demotes channels to being "inactive" after they have not received traffic for 180 days. However, upon doing so, an event was sent to...
CVE-2024-56136
- EPSS 0.15%
- Veröffentlicht 16.01.2025 20:15:33
- Zuletzt bearbeitet 27.09.2025 00:16:08
Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above are vulnerable to an information disclose attack, where, if a Zulip server is hosting multiple organizations, an unauthenticated u...