Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replaceemojiwithtext function in uiutil.ts.