Vulnerabilities > Zulip

DATE CVE VULNERABILITY TITLE RISK
2022-01-20 CVE-2021-3866 Unspecified vulnerability in Zulip
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.
network
low complexity
zulip
5.4
2021-12-02 CVE-2021-43791 Unspecified vulnerability in Zulip
Zulip is an open source group chat application that combines real-time chat with threaded conversations.
network
low complexity
zulip
5.3
2021-10-07 CVE-2021-41115 Unspecified vulnerability in Zulip
Zulip is an open source team chat server.
network
low complexity
zulip
6.5
2021-04-15 CVE-2021-30487 Unspecified vulnerability in Zulip Server 3.0/3.1
In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.
network
low complexity
zulip
2.7
2021-04-15 CVE-2021-30479 Improper Privilege Management vulnerability in Zulip Server
An issue was discovered in Zulip Server before 3.4.
network
low complexity
zulip CWE-269
5.3
2021-04-15 CVE-2021-30478 Improper Privilege Management vulnerability in Zulip Server
An issue was discovered in Zulip Server before 3.4.
network
low complexity
zulip CWE-269
4.3
2021-04-15 CVE-2021-30477 Unspecified vulnerability in Zulip Server
An issue was discovered in Zulip Server before 3.4.
network
low complexity
zulip
4.3
2021-02-05 CVE-2020-10858 Missing Authorization vulnerability in Zulip Desktop
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
network
low complexity
zulip CWE-862
5.3
2021-02-05 CVE-2020-10857 Unspecified vulnerability in Zulip Desktop
Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.
network
low complexity
zulip
critical
9.8
2020-08-21 CVE-2020-15070 Code Injection vulnerability in Zulip Server
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
network
low complexity
zulip CWE-94
8.8