Zulip Server
Vendor:
First CVE: Mar 28, 2017 · Active for 9 years
40
Total CVEs
More Total CVEs than 98% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Zulip Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2017
9 years ago
Most Recent CVE
May 12, 2026
77 days ago
CVE Severity & Scoring
Zulip Server40 CVEs
10%
73%
13%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network40 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (97.5%)
High1 (2.5%)
Unknown0 (0.0%)
User Interaction
None24 (60.0%)
Unknown0 (0.0%)
Required16 (40.0%)
Privileges Required
Low19 (47.5%)
High4 (10.0%)
None17 (42.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21706CRITICAL Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invita | Feb 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-18933CRITICAL In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or | Nov 21, 2019 | 9.8 | 30 | NO | NO |
CVE-2026-40300MEDIUM Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical c | May 12, 2026 | 6.5 | 24 | NO | NO |
CVE-2025-31478HIGH Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authent | Apr 16, 2025 | 8.2 | 23 | NO | NO |
CVE-2020-14215HIGH Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations. | Aug 21, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-15070HIGH Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field | Aug 21, 2020 | 8.8 | 22 | NO | NO |
CVE-2019-16215MEDIUM The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message | Sep 18, 2019 | 6.5 | 22 | NO | NO |
CVE-2017-0910HIGH In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on | Nov 27, 2017 | 8.8 | 22 | NO | NO |
CVE-2024-36612HIGH Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers. | Nov 29, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-32678MEDIUM Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed f | Aug 25, 2023 | 6.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Zulip Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 1 | 6.1 | 0.6% | 0 | 0 |
| 2023-01-09 | 1 | 4.6 | 0.5% | 0 | 0 |
| 2.0.0 | 1 | 5.4 | 0.2% | 0 | 0 |
| 1.5.1 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.5.0 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.4.3 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.4.2 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.4.1 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.4.0 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.9 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.8 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.7 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.6 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.4 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.3 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.2 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.13 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.12 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.11 | 1 | 6.5 | 1.3% | 0 | 0 |
| 1.3.10 | 1 | 6.5 | 1.3% | 0 | 0 |