Vulnerabilities > Zulip > Zulip Server > 1.7.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-04-20 | CVE-2020-9444 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Zulip Server Zulip Server before 2.1.3 allows reverse tabnabbing via the Markdown functionality. | 6.1 |
2020-04-20 | CVE-2020-10935 | Cross-site Scripting vulnerability in Zulip Server Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover. | 5.4 |
2019-11-21 | CVE-2019-18933 | Unspecified vulnerability in Zulip Server In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account. | 9.8 |
2019-09-18 | CVE-2019-16215 | Unspecified vulnerability in Zulip Server The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. | 6.5 |
2018-04-18 | CVE-2018-9999 | Cross-site Scripting vulnerability in Zulip Server In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend. | 5.4 |
2018-04-18 | CVE-2018-9990 | Cross-site Scripting vulnerability in Zulip Server In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead. | 6.1 |
2018-04-18 | CVE-2018-9987 | Cross-site Scripting vulnerability in Zulip Server In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications. | 6.1 |
2018-04-18 | CVE-2018-9986 | Cross-site Scripting vulnerability in Zulip Server In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor. | 6.1 |