Zulip Server

Vendor:

First CVE: Mar 28, 2017 · Active for 9 years

40
Total CVEs
More Total CVEs than 98% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Zulip Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2017
9 years ago
Most Recent CVE
May 12, 2026
77 days ago

CVE Severity & Scoring

Zulip Server40 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network40 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (97.5%)
High1 (2.5%)
Unknown0 (0.0%)
User Interaction
None24 (60.0%)
Unknown0 (0.0%)
Required16 (40.0%)
Privileges Required
Low19 (47.5%)
High4 (10.0%)
None17 (42.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invita
Feb 26, 20229.831NONO
In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or
Nov 21, 20199.830NONO
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical c
May 12, 20266.524NONO
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authent
Apr 16, 20258.223NONO
Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.
Aug 21, 20207.523NONO
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field
Aug 21, 20208.822NONO
The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message
Sep 18, 20196.522NONO
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on
Nov 27, 20178.822NONO
Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
Nov 29, 20247.521NONO
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed f
Aug 25, 20236.521NONO

Exploit Exposure

Signals from CVEs in this product scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (40 CVEs).

Media Mentions

Signals from CVEs in this product scope (40 CVEs).

Top CNAs Publishing CVEs For Zulip Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.016.10.6%00
2023-01-0914.60.5%00
2.0.015.40.2%00
1.5.116.51.3%00
1.5.016.51.3%00
1.4.316.51.3%00
1.4.216.51.3%00
1.4.116.51.3%00
1.4.016.51.3%00
1.3.916.51.3%00
1.3.816.51.3%00
1.3.716.51.3%00
1.3.616.51.3%00
1.3.416.51.3%00
1.3.316.51.3%00
1.3.216.51.3%00
1.3.1316.51.3%00
1.3.1216.51.3%00
1.3.1116.51.3%00
1.3.1016.51.3%00