Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zulip zulip vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2021-43791
Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected versions expiration dates on the confirmation objects associated with email invitations were not enforced properly in the new account registration flow. A confirma...
Zulip Zulip
9.8
CVSSv3
CVE-2021-43799
Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server before 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which RabbitMQ...
Zulip Zulip
8.8
CVSSv3
CVE-2021-3967
Improper Access Control in GitHub repository zulip/zulip before 4.10.
Zulip Zulip
4.3
CVSSv3
CVE-2016-4426
In zulip prior to 1.3.12, bot API keys were accessible to other users in the same realm.
Zulip Zulip
7.5
CVSSv3
CVE-2016-4427
In zulip prior to 1.3.12, deactivated users could access messages if SSO was enabled.
Zulip Zulip
4.3
CVSSv3
CVE-2021-30477
An issue exists in Zulip Server prior to 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send mes...
Zulip Zulip Server
4.3
CVSSv3
CVE-2021-30478
An issue exists in Zulip Server prior to 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, including to other organizations ho...
Zulip Zulip Server
4.3
CVSSv3
CVE-2023-47642
Zulip is an open-source team collaboration tool. It exists by the Zulip development team that active users who had previously been subscribed to a stream incorrectly continued being able to use the Zulip API to access metadata for that stream. As a result, users who had been remo...
Zulip Zulip Server
9.8
CVSSv3
CVE-2020-10857
Zulip Desktop prior to 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.
Zulip Zulip Desktop
5.4
CVSSv3
CVE-2020-10935
Zulip Server prior to 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
Zulip Zulip Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
HTML injection
CVE-2024-35894
SQL
CVE-2024-5105
CVE-2014-100005
CVE-2024-35895
unauthorized
CVE-2024-22120
CVE-2024-35890
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »