Zulip is a team-collaboration and messaging platform whose vulnerability profile spans a narrow product line centered on its core server and desktop client offerings, yet achieves prominence within the collaboration-software landscape. Vulnerabilities affecting the vendor lean toward moderate severity outcomes and cluster around web-application and access-control weaknesses: cross-site scripting, insufficient authorization, and exposure of sensitive information recur across the platform. These weakness classes are characteristic of web-facing communication systems where input handling, session management, and access boundaries are integral to security. Defenders deploying Zulip instances should prioritize inventory and patching of the server component and apply standard input-validation hardening practices; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zulip over time
Signals from CVEs in this vendor scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43799CRITICAL Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (un | Jan 25, 2022 | 9.8 | 34 | NO | NO |
CVE-2022-21706CRITICAL Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invita | Feb 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-18933CRITICAL In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or | Nov 21, 2019 | 9.8 | 30 | NO | NO |
CVE-2021-3967HIGH Improper Access Control in GitHub repository zulip/zulip prior to 4.10. | Feb 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-31168HIGH Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants org | Jul 22, 2022 | 8.8 | 26 | NO | NO |
CVE-2016-4427HIGH In zulip before 1.3.12, deactivated users could access messages if SSO was enabled. | Jul 28, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-10857CRITICAL Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution. | Feb 5, 2021 | 9.8 | 25 | NO | NO |
CVE-2026-40300MEDIUM Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical c | May 12, 2026 | 6.5 | 24 | NO | NO |
CVE-2022-24751HIGH Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable to a race condition during account deactivation, where a si | Mar 16, 2022 | 7.4 | 24 | NO | NO |
CVE-2025-31478HIGH Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authent | Apr 16, 2025 | 8.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (62 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zulip.
Media articles that mention a CVE ID that affects a product developed by Zulip — matched by CVE ID, not by vendor name.