Vulnerabilities
53 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-67809 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked. NVD description · AI analysis pending | 4.7 | <1% |
| — | ||
| CVE-2024-45515 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can exploit this issue by crafting a file with manipulated metadata, allowing them to bypass content type checks and execute arbitrary JavaScript within the victim's session. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2025-27914 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth token and involves a crafted URL with manipulated query parameters that triggers XSS when accessed by a victim. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-9665 | Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability. Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message. The specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account. Was ZDI-CAN-23939. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2024-45518 | Authenticated SSRF in Zimbra Collaboration Suite can chain to RCE Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) flaw, CVE-2024-45518, caused by improper input sanitization and a misconfigured domain whitelist. An authenticated user with only low-level privileges can trigger the flaw to make the Zimbra server send unauthorized HTTP requests to services on the internal network. By chaining the SSRF with command injection in a reachable internal service, the attacker can achieve remote code execution; combining the SSRF with existing cross-site scripting vulnerabilities also yields RCE. All supported ZCS branches are affected: 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the elevated EPSS score (20.7% probability of exploitation in 30 days, 97th percentile) indicates significant exploitation risk. Do: Upgrade to ZCS 10.1.1, 10.0.9, 9.0.0 Patch 41, or 8.8.15 Patch 46 (or later) to remediate. Until patched, enforce a strict and correctly configured domain whitelist for the affected feature, map which internal services the Zimbra host can reach, and monitor for anomalous internal HTTP requests originating from the server. Since authentication is required, review accounts on internet-exposed webmail for low-privilege or compromised credentials that could be used as a launch point. | 8.8 | 21% |
| largetens of thousands of deployments (public internet scans typically index roughly 30,000-50,000 exposed Zimbra servers) | ||
| CVE-2024-27442 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations. However, an attacker can escalate privileges from the zimbra user to root, because of improper handling of input arguments. An attacker can execute arbitrary commands with elevated privileges, leading to local privilege escalation. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2024-27443 | Cross-Site Scripting in Zimbra Collaboration Suite CalendarInvite (Classic Webmail) CVE-2024-27443 is a cross-site scripting vulnerability (CWE-79) in the CalendarInvite feature of the Zimbra webmail classic user interface in Synacor Zimbra Collaboration Suite (ZCS). It is triggered when a user's browser renders an email containing a crafted calendar header, causing attacker-controlled JavaScript to execute within the webmail session. Successful exploitation allows an attacker to run arbitrary JavaScript in the victim's browser, enabling session/cookie theft and actions performed as the victim inside webmail; no public proof-of-concept is known and CVSS has not yet been scored. Organizations running ZCS where users access mail through the classic webmail UI are affected (deployments restricted to the modern UI are not impacted), though specific affected version ranges have not been published in the available data. The flaw was added to the CISA KEV catalog on 2025-05-19, confirming exploitation in the wild, and EPSS currently estimates a 23.6% probability of exploitation within 30 days (98th percentile). Do: Update ZCS to the patched release for your branch per Synacor/Zimbra's security advisory (specific fixed version numbers are not included in the available data) and confirm whether the classic webmail UI is enabled for any users. Review webmail access logs for suspicious calendar-invite traffic, and note that federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable. | 6.1 | 24% | KEV |
| mass≈ mass | |
| CVE-2023-26562 | In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp. In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2017-20188 | A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerability is the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js. The manipulation of the argument message leads to cross site scripting. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 8.8.2 is able to address this issue. The identifier of the patch is 8d039d6efe80780adc40c6f670c06d21de272105. It is recommended to upgrade the affected component. The identifier VDB-249421 was assigned to this vulnerability. NVD description · AI analysis pending | 4.7 | <1% |
| — | ||
| CVE-2023-41106 | An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42. NVD description · AI analysis pending | 7.5 group max | 1% |
| — | ||
| CVE-2023-38750 | In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed. In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-29381 | An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2023-24032 | In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by pass In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege escalation (LPE). NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2022-45913 +1 in the same advisory: …45911 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0. An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execute arbitrary JavaScript code, leading to information disclosure. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-45912 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for remote code execution. NVD description · AI analysis pending | 7.2 | 1% |
| — | ||
| CVE-2022-41351 | In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value o In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default value of 10). NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-41347 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the zimbra user to execute the NGINX binary as root with arbitrary parameters. As part of its intended functionality, NGINX can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2022-37393 | Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root. NVD description · AI analysis pending | 7.8 | 2% | PoC ×3 |
| — | |
| CVE-2022-37041 | An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. The value of the X-Forwarded-Host header overwrites the value of the Host header in proxied requests. The value of X-Forwarded-Host header is not checked against the whitelist of hosts that ZCS is allowed to proxy to (the zimbraProxyAllowedDomains setting). NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2022-32294 | Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port). NOTE: a third party reports that this cannot be reproduced. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2021-35209 | An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host header overwrites the value of the Host header in proxied requests. The value of X-Host header is not checked against the whitelist of hosts Zimbra is allowed to proxy to (the zimbraProxyAllowedDomains setting). NVD description · AI analysis pending | 9.8 group max | 3% | PoC |
| — | |
| CVE-2020-35123 | In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17. NVD description · AI analysis pending | 6.5 | 1% |
| — | ||
| CVE-2020-11737 | A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execut A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element containing an href attribute with a "www" substring (including the quotes) followed immediately by a DOM event listener such as onmouseover. This is fixed in 9.0.0 Patch 2. NVD description · AI analysis pending | 6.1 | 2% |
| — | ||
| CVE-2020-10194 | cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user must match the domain of the galsync account in the request. NVD description · AI analysis pending | 6.5 | 1% |
| — | ||
| CVE-2019-8947 | Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS. Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS. NVD description · AI analysis pending | 6.1 | 1% |
| — |