Zimbra Collaboration vulnerabilities
50 known vulnerabilities affecting zimbra/collaboration.
Total CVEs
50
CISA KEV
3
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL4HIGH11MEDIUM31LOW4
Vulnerabilities
Page 3 of 3
CVE-2022-41349P4MEDIUMCVSS 6.1v8.8.152022-10-12
CVE-2022-41349 [MEDIUM] CWE-79 CVE-2022-41349: In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter tha
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
nvd
CVE-2024-33533P4MEDIUMCVSS 5.4≥ 10.0.0, < 10.0.8v9.0.02024-08-12
CVE-2024-33533 [MEDIUM] CWE-79 CVE-2024-33533: An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in the Zimbra webmail admin interface. This vulnerability occurs due to inadequate input validation of the packages parameter, allowing an authenticated attacker to inject and execute arbitrary Jav
nvd
CVE-2022-41350P4MEDIUMCVSS 6.1v8.8.152022-10-12
CVE-2022-41350 [MEDIUM] CWE-79 CVE-2022-41350: In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone
In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
nvd
CVE-2023-45206P4MEDIUMCVSS 6.1≥ 10.0.0, < 10.0.5v8.8.15+1 more2024-02-13
CVE-2023-45206 [MEDIUM] CWE-79 CVE-2023-45206: An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help docume
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malicious code will mitigate this issue.)
nvd
CVE-2025-27914P4MEDIUMCVSS 5.4≥ 10.0.0, < 10.0.11v9.0.0+1 more2025-03-12
CVE-2025-27914 [MEDIUM] CWE-79 CVE-2025-27914: An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth token and involves a crafted URL with manipulated query p
nvd
CVE-2022-41348P4MEDIUMCVSS 6.1v9.0.02022-10-12
CVE-2022-41348 [MEDIUM] CWE-79 CVE-2022-41348: An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute o
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosure.
nvd
CVE-2026-73573P4LOWCVSS 3.1fixed in 10.1.172026-08-13
CVE-2026-73573 [LOW] CWE-24 CVE-2026-73573: In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Br
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive
nvd
CVE-2026-73571P4LOWCVSS 3.1fixed in 10.1.172026-08-13
CVE-2026-73571 [LOW] CWE-863 CVE-2026-73571: An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to imp
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. Thi
nvd
CVE-2026-73574P4LOWCVSS 3.1fixed in 10.1.172026-08-13
CVE-2026-73574 [LOW] CWE-669 CVE-2026-73574: In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zim
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xm
nvd
CVE-2026-73575P4LOWCVSS 3.1fixed in 10.1.172026-08-13
CVE-2026-73575 [LOW] CWE-352 CVE-2026-73575: In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exis
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially all
nvd
← Previous3 / 3