CVEs we hold for Zulip
Records whose assigning authority named Zulip as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-40300Zulip: Message edit history visible in "moves only" policy through /api/v1/messages/{id}/historyzulip
CVE-2026-25741Zulip Vulnerable to Modification of Payment Method (Stripe Default Card) by Non-Billing Userszulip
CVE-2025-47930Zulip Server has access control bypass for restrictions on creation of specific channel typeszulip
CVE-2025-30369Zulip allows the deletion of Custom profile fields by administrators of a different organizationzulip
CVE-2025-30368Zulip allows the deletion of organization by administrators of a different organizationzulip
CVE-2024-56136/api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account in Zulip serverzulip
CVE-2024-21630Zulip non-admins can invite new users to streams they would not otherwise be able to add existing users tozulip
CVE-2023-33186Cross-site scripting vulnerability in Zulip Server development branch via topic tooltipzulip
CVE-2023-32678Zulip vulnerable to insufficient authorization check for edition/deletion of messages and topics in private streams by…zulip
CVE-2023-32677Users who can send invitations can erroneously add users to streams during invitation in Zulipzulip
CVE-2023-22735User uploads proxied from S3 lack `Content-Security-Policy` headers, may be served with `Content-Disposition: inline`…zulip
40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.