VYPR

Zimbra Collaboration (ZCS)

by Zimbra

CVEs (120)

  • CVE-2015-2249MedJan 27, 2020
    risk 0.35cvss 5.4epss 0.01

    Zimbra Collaboration before 8.6.0 patch5 has XSS.

  • CVE-2019-6981MedMay 29, 2019
    risk 0.35cvss 6.5epss 0.01

    Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.

  • CVE-2018-10950MedMay 10, 2018
    risk 0.35cvss 5.3epss 0.01

    mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump.

  • CVE-2025-25065MedFeb 3, 2025
    risk 0.34cvss 5.3epss 0.01

    SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

  • CVE-2018-17938MedOct 3, 2018
    risk 0.34cvss 5.3epss 0.01

    Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.

  • CVE-2025-62763MedOct 21, 2025
    risk 0.33cvss 5.0epss 0.00

    Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

  • CVE-2018-14013MedMay 29, 2019
    risk 0.33cvss 6.1epss 0.07

    Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.

  • CVE-2025-67809MedDec 15, 2025
    risk 0.31cvss 4.7epss 0.00

    An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party…

  • CVE-2024-45513MedNov 21, 2024
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This allows an attacker to inject and execute arbitrary JavaScript code in the context of the…

  • CVE-2024-45194MedNov 21, 2024
    risk 0.31cvss 4.8epss 0.00

    In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrative access to the Zimbra Administration Panel can inject malicious JavaScript code while configuring…

  • CVE-2019-12427MedJan 27, 2020
    risk 0.31cvss 4.8epss 0.01

    Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.

  • CVE-2026-33371MedMar 20, 2026
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is…

  • CVE-2026-33369MedMar 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search filter. An authenticated…

  • CVE-2026-73575LowAug 13, 2026
    risk 0.20cvss 3.1epss 0.00

    In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by…

  • CVE-2026-73574LowAug 13, 2026
    risk 0.20cvss 3.1epss 0.00

    In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially…

  • CVE-2026-73573LowAug 13, 2026
    risk 0.20cvss 3.1epss 0.00

    In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path…

  • CVE-2026-73571LowAug 13, 2026
    risk 0.20cvss 3.1epss 0.00

    An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send…

  • CVE-2022-3569HigOct 17, 2022
    risk 0.03cvss 7.8epss 0.01

    Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

  • CVE-2012-1213Feb 24, 2012
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.

  • CVE-2008-1226Mar 10, 2008
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration Suite (ZCS) 4.0.3, 4.5.6, and possibly other versions before 4.5.10 allow remote attackers to inject arbitrary web script or HTML via an e-mail attachment, possibly involving a (1) .jpg or (2) .gif image…

Page 6 of 6