Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zulip server vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2020-15070
Zulip Server 2.x prior to 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
Zulip Zulip Server
4.3
CVSSv2
CVE-2020-12759
Zulip Server prior to 2.1.5 allows reflected XSS via the Dropbox webhook.
Zulip Zulip Server
5.8
CVSSv2
CVE-2020-14194
Zulip Server prior to 2.1.5 allows reverse tabnapping via a topic header link.
Zulip Zulip Server
5
CVSSv2
CVE-2020-14215
Zulip Server prior to 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
Zulip Zulip Server
4.3
CVSSv2
CVE-2020-9445
Zulip Server prior to 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
Zulip Zulip Server
3.5
CVSSv2
CVE-2020-10935
Zulip Server prior to 2.1.3 allows XSS via a Markdown link, with resultant account takeover.
Zulip Zulip Server
5.8
CVSSv2
CVE-2020-9444
Zulip Server prior to 2.1.3 allows reverse tabnabbing via the Markdown functionality.
Zulip Zulip Server
5.8
CVSSv2
CVE-2019-19775
The image thumbnailing handler in Zulip Server versions 1.9.0 to prior to 2.0.8 allowed an open redirect that was visible to logged-in users.
Zulip Zulip Server
2 Github repositories
7.5
CVSSv2
CVE-2019-18933
In Zulip Server versions from 1.7.0 to prior to 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal...
Zulip Zulip Server
3.5
CVSSv2
CVE-2019-16216
Zulip server prior to 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attack on other logged-in users. On a Zulip server using the default local uploads ...
Zulip Zulip Server
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »