Synacor

Zimbra Collaboration Suite

82 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 30.03.2026 15:16:29
  • Zuletzt bearbeitet 07.04.2026 18:50:47

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state trans...

  • EPSS 0.03%
  • Veröffentlicht 20.03.2026 14:16:16
  • Zuletzt bearbeitet 01.04.2026 15:32:50

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The application accepts CSRF tokens supplied within the request...

  • EPSS 0.05%
  • Veröffentlicht 20.03.2026 14:16:16
  • Zuletzt bearbeitet 01.04.2026 15:35:47

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submi...

  • EPSS 0.03%
  • Veröffentlicht 20.03.2026 14:16:16
  • Zuletzt bearbeitet 01.04.2026 15:36:22

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient sanitization of specific uploaded file types. When a user opens a public...

  • EPSS 0.05%
  • Veröffentlicht 20.03.2026 14:16:16
  • Zuletzt bearbeitet 01.04.2026 15:36:59

Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search ...

  • EPSS 0.08%
  • Veröffentlicht 20.03.2026 14:16:15
  • Zuletzt bearbeitet 01.04.2026 15:37:25

Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanitize user-supplied input, allowing an unauthenticated ...

Warnung Medienbericht
  • EPSS 10.01%
  • Veröffentlicht 05.01.2026 00:00:00
  • Zuletzt bearbeitet 18.03.2026 20:13:37

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Warnung Medienbericht
  • EPSS 50.07%
  • Veröffentlicht 22.12.2025 18:16:17
  • Zuletzt bearbeitet 23.01.2026 18:39:33

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can...

  • EPSS 0.05%
  • Veröffentlicht 23.06.2025 00:00:00
  • Zuletzt bearbeitet 11.07.2025 14:32:05

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leadin...

  • EPSS 0.28%
  • Veröffentlicht 14.05.2025 00:00:00
  • Zuletzt bearbeitet 11.06.2025 21:20:29

An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbi...