vciy

CVEs we hold for Zulip

Records whose assigning authority named Zulip as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-40300Zulip: Message edit history visible in "moves only" policy through /api/v1/messages/{id}/historyzulip
CVE-2026-26058Zulip: Path Traversal in Importzulip
CVE-2026-25742Zulip: Anonymous File Access After Disabling Spectator Accesszulip
CVE-2026-25741Zulip Vulnerable to Modification of Payment Method (Stripe Default Card) by Non-Billing Userszulip
CVE-2026-24050Zulip affected by Stored XSS in user profile modalzulip
CVE-2025-52559Zulip XSS in digest preview URLzulip
CVE-2025-47930Zulip Server has access control bypass for restrictions on creation of specific channel typeszulip
CVE-2025-31478Zulip Authentication Backend Configuration Bypasszulip
CVE-2025-30369Zulip allows the deletion of Custom profile fields by administrators of a different organizationzulip
CVE-2025-30368Zulip allows the deletion of organization by administrators of a different organizationzulip
CVE-2025-27149Zulip exports can leak private datazulip
CVE-2025-25195Zulip events can leak private channel nameszulip
CVE-2024-56136/api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account in Zulip serverzulip
CVE-2024-27286Moving single messages from public to private streams leaves them accessiblezulip
CVE-2024-21630Zulip non-admins can invite new users to streams they would not otherwise be able to add existing users tozulip
CVE-2023-47642Stream description leaks to ex-subscribers in Zulipzulip
CVE-2023-33186Cross-site scripting vulnerability in Zulip Server development branch via topic tooltipzulip
CVE-2023-32678Zulip vulnerable to insufficient authorization check for edition/deletion of messages and topics in private streams by…zulip
CVE-2023-32677Users who can send invitations can erroneously add users to streams during invitation in Zulipzulip
CVE-2023-28623Unauthorized user can register an account in specific configurations in Zulipzulip
CVE-2023-22735User uploads proxied from S3 lack `Content-Security-Policy` headers, may be served with `Content-Disposition: inline`…zulip
CVE-2022-41914Non-constant-time SCIM token comparison in Zulip Serverzulip
CVE-2022-36048IP address leak via image proxy bypass in Zulip Serverzulip
CVE-2022-35962Crafted link in Zulip message can cause disclosure of credentialszulip-mobile
CVE-2022-31168Zulip Server insufficient authorization for changing bot roleszulip
CVE-2022-31134Zulip Server public data export contains attachments that are non-publiczulip
CVE-2022-31017Expression Always True vulnerability in Zulip Serverzulip
CVE-2022-24751Race condition in Zulipzulip
CVE-2022-23656Cross-site scripting vulnerability in Zulip Serverzulip
CVE-2022-21706Multi-use invitations can grant access to other organizations in Zulipzulip
CVE-2021-43799RabbitMQ exposes ports with weak default secrets in Zulip Serverzulip
CVE-2021-43791Ineffective expiration validation for invitation links in Zulipzulip
CVE-2021-41115Regular expression denial-of-service in Zulipzulip
CVE-2021-3967Improper Access Control in zulip/zulipzulip/zulip
CVE-2021-3866Cross-site Scripting (XSS) - Stored in zulip/zulipzulip/zulip
CVE-2017-0910no title heldZulip Server
CVE-2017-0896no title heldZulip Server
CVE-2017-0881no title heldn/a Zulip Server Versions 1.4.2 and below
CVE-2016-4427no title heldn/a zulip
CVE-2016-4426no title heldn/a zulip

40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.