In Zulip Server versions prior to 1.7.2, there were XSS issues with the frontend markdown processor.
zulip zulip server