Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zulip

First CVE: Mar 28, 2017Active for: 9 yearsTotal CVEs: 62
19.5
VTI Score
Low

Zulip is a team-collaboration and messaging platform whose vulnerability profile spans a narrow product line centered on its core server and desktop client offerings, yet achieves prominence within the collaboration-software landscape. Vulnerabilities affecting the vendor lean toward moderate severity outcomes and cluster around web-application and access-control weaknesses: cross-site scripting, insufficient authorization, and exposure of sensitive information recur across the platform. These weakness classes are characteristic of web-facing communication systems where input handling, session management, and access boundaries are integral to security. Defenders deploying Zulip instances should prioritize inventory and patching of the server component and apply standard input-validation hardening practices; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
62
Total CVEs
More Total CVEs than 99% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zulip over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2017
9 years ago
Most Recent CVE
May 12, 2026
74 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (62 CVEs).

62 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-43799CRITICAL
Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (un
Jan 25, 20229.834NONO
CVE-2022-21706CRITICAL
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invita
Feb 26, 20229.831NONO
CVE-2019-18933CRITICAL
In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or
Nov 21, 20199.830NONO
CVE-2021-3967HIGH
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
Feb 26, 20228.828NONO
CVE-2022-31168HIGH
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants org
Jul 22, 20228.826NONO
CVE-2016-4427HIGH
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
Jul 28, 20227.525NONO
CVE-2020-10857CRITICAL
Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.
Feb 5, 20219.825NONO
CVE-2026-40300MEDIUM
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical c
May 12, 20266.524NONO
CVE-2022-24751HIGH
Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during account deactivation, where a si
Mar 16, 20227.424NONO
CVE-2025-31478HIGH
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authent
Apr 16, 20258.223NONO
View all 62 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products62 CVEs
13%
66%
15%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.6%)
Network61 (98.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low57 (91.9%)
High5 (8.1%)
Unknown0 (0.0%)
User Interaction
None40 (64.5%)
Unknown0 (0.0%)
Required22 (35.5%)
Privileges Required
Low30 (48.4%)
High5 (8.1%)
None27 (43.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (62 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zulip.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zulip — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zulip's Products

View all 5 CNAs →

Top CWEs