Skip to main content

Vendor/product archive

synacor / zimbra_collaboration_suite CVEs

Beta · best-effort

82 CVEs tagged to synacor / zimbra_collaboration_suite12 Critical, 19 High, 51 Medium, 0 Low, 0 Unrated.

CVE-2026-33373

Published Mar 30, 2026

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentic…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-33372

Published Mar 20, 2026

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-33371

Published Mar 20, 2026

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-33370

Published Mar 20, 2026

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient s…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-33369

Published Mar 20, 2026

Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sa…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-33368

Published Mar 20, 2026

Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-66376

Published Jan 5, 2026

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

CVSS 7.2 · High
evidence mentions
20
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-68645

Published Dec 22, 2025

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request param…

CVSS 8.8 · High
evidence mentions
3
Buzz score
45.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-48700

Published Jun 23, 2025

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to exe…

CVSS 6.1 · Medium
evidence mentions
8
Buzz score
66.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-45516

Published May 14, 2025

An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS)…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32354

Published Apr 29, 2025

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-27915

Published Mar 12, 2025

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient…

CVSS 5.4 · Medium
evidence mentions
12
Buzz score
70.7
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-25065

Published Feb 3, 2025

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to interna…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-25064

Published Feb 3, 2025

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient sanitization of a us…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-54663

Published Dec 19, 2024

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45517

Published Nov 21, 2024

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin panel interf…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45513

Published Nov 21, 2024

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webma…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45194

Published Nov 21, 2024

In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with administrativ…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45514

Published Nov 21, 2024

An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficien…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45512

Published Nov 21, 2024

An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malic…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45510

Published Nov 20, 2024

An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitiza…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45511

Published Nov 20, 2024

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization o…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50599

Published Nov 7, 2024

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises f…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45519

Published Oct 2, 2024

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated us…

CVSS 10.0 · Critical
evidence mentions
7
Buzz score
58.8
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 82 CVEsPage 1 of 4