CVE-2024-36625
- EPSS 0.09%
- Published 29.11.2024 17:15:07
- Last modified 29.11.2024 18:15:08
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.
CVE-2024-27286
- EPSS 0.06%
- Published 20.03.2024 20:15:08
- Last modified 03.09.2025 14:30:33
Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, move only subsequent messages as well, or move just a single message. If the user chose to just move one mess...
CVE-2023-28623
- EPSS 0.05%
- Published 19.05.2023 22:15:09
- Last modified 21.11.2024 07:55:41
Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of `ZulipLDAPAuthBackend` and `EmailAuthBackend`) are the only ones enabl...
CVE-2023-32677
- EPSS 0.05%
- Published 19.05.2023 21:15:08
- Last modified 21.11.2024 08:03:49
Zulip is an open-source team collaboration tool with unique topic-based threading. Zulip administrators can configure Zulip to limit who can add users to streams, and separately to limit who can invite users to the organization. In Zulip Server 6.1 a...
CVE-2022-36048
- EPSS 0.25%
- Published 31.08.2022 20:15:08
- Last modified 21.11.2024 07:12:15
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying messages with embedded remote images, Zulip normally loads the image preview via a go-camo proxy server. However, an attacker who...
CVE-2022-35962
- EPSS 0.55%
- Published 29.08.2022 15:15:10
- Last modified 21.11.2024 07:12:03
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version 27.189, a crafted link in a message sent by an authenticated user could lead to credential disclosure if a user follows the link. ...
CVE-2016-4427
- EPSS 0.27%
- Published 28.07.2022 17:15:08
- Last modified 21.11.2024 02:52:08
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
CVE-2016-4426
- EPSS 0.15%
- Published 28.07.2022 17:15:08
- Last modified 21.11.2024 02:52:08
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.
CVE-2022-31168
- EPSS 0.27%
- Published 22.07.2022 13:15:08
- Last modified 21.11.2024 07:04:02
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerabi...
CVE-2022-31017
- EPSS 0.17%
- Published 25.06.2022 09:15:09
- Last modified 21.11.2024 07:03:43
Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic error. A stream configured as private with protected history, where new subscribers should not be allowed to see messages sent before ...