Zulip server
This hub aggregates every CVE we track for Zulip server, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
41
CVEs tracked
1
Critical
8
High
0
In CISA KEV
Severity distribution
MEDIUM28HIGH8LOW4CRITICAL1
Monthly trend
0
0
0
0
1
0
1
0
2
1
0
0
1
0
0
0
0
0
0
1
0
0
1
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Zulip server.
- CVE-2026-40300Zulip: Message edit history visible in "moves only" policy through /api/v1/messages/{id}/history6.5
- CVE-2026-24050Zulip affected by Stored XSS in user profile modal5.4
- CVE-2025-52559Zulip XSS in digest preview URL6.8
- CVE-2025-31478Zulip Authentication Backend Configuration Bypass8.2
- CVE-2025-30369Zulip allows the deletion of Custom profile fields by administrators of a different organization2.7
- CVE-2025-27149Zulip exports can leak private data2.7
- CVE-2024-56136/api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account in Zulip server5.3
- CVE-2024-36612Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.7.5
- CVE-2024-27286Moving single messages from public to private streams leaves them accessible6.5
- CVE-2024-21630Zulip non-admins can invite new users to streams they would not otherwise be able to add existing users to4.3
- CVE-2023-47642Stream description leaks to ex-subscribers in Zulip4.3
- CVE-2023-32678Zulip vulnerable to insufficient authorization check for edition/deletion of messages and topics in private streams by former subscribers6.5
- CVE-2023-33186Cross-site scripting vulnerability in Zulip Server development branch via topic tooltip8.2
- CVE-2023-22735User uploads proxied from S3 lack `Content-Security-Policy` headers, may be served with `Content-Disposition: inline` in zulip4.4
- CVE-2022-41914Non-constant-time SCIM token comparison in Zulip Server3.7
Product normalization is registry-driven with AI assist and human review. How it works