📦 Zulip Server

by Zulip

🔍 What is Zulip Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-36612

HIGH CVSS 7.5 Nov 29, 2024

Zulip versions 8.0 through 8.3 contain a memory leak vulnerability in popover handling that allows attackers to gradually exhaust server memory through repeated triggering. This affects all Zulip serv...

CVE-2023-33186

HIGH CVSS 8.2 May 30, 2023

This cross-site scripting (XSS) vulnerability in Zulip Server allows attackers to inject malicious JavaScript into topic tooltips. When a victim hovers over a specially crafted topic in their message ...

CVE-2022-21706

HIGH CVSS 7.2 Feb 26, 2022

This vulnerability in Zulip Server allows multi-use invitations created in one organization to be used to join any other organization on the same deployment. This bypasses email domain restrictions, g...

CVE-2026-24050

MEDIUM CVSS 5.4 Feb 6, 2026

This stored cross-site scripting (XSS) vulnerability in Zulip allows attackers to inject malicious scripts into group or channel names. When administrators perform user profile actions, these scripts ...

CVE-2024-56136

MEDIUM CVSS 5.3 Jan 16, 2025

CVE-2024-56136 is an information disclosure vulnerability in Zulip Server that allows unauthenticated attackers to determine if specific email addresses are registered on multi-organization instances....