Zulipchat develops a team-collaboration and messaging platform available as both cloud-hosted and self-hosted deployments, with exposure observed in its desktop client. The vendor's disclosed vulnerabilities center on web-application input handling and certificate validation, reflecting the attack surface inherent to a browser-based communication tool. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zulipchat over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12637CRITICAL Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option. | May 9, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-9443MEDIUM Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Z | Mar 18, 2020 | 6.1 | 21 | NO | NO |
CVE-2020-24582MEDIUM Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface. | Sep 10, 2020 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zulipchat.
Media articles that mention a CVE ID that affects a product developed by Zulipchat — matched by CVE ID, not by vendor name.