Zimbra

Zimbra Collaboration Suite

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.46%
  • Veröffentlicht 24.03.2026 15:21:05
  • Zuletzt bearbeitet 25.03.2026 16:16:08

Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519.

  • EPSS 0.08%
  • Veröffentlicht 20.03.2026 14:16:15
  • Zuletzt bearbeitet 01.04.2026 15:37:25

Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanitize user-supplied input, allowing an unauthenticated ...

  • EPSS 0.02%
  • Veröffentlicht 17.09.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureResetPasswordStatus attribute is enabled. An attacker can exploit this by tricking an authenticated use...

  • EPSS 0.1%
  • Veröffentlicht 16.09.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (ei...

  • EPSS 0.1%
  • Veröffentlicht 30.07.2025 00:00:00
  • Zuletzt bearbeitet 07.08.2025 18:16:45

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can...

  • EPSS 0.37%
  • Veröffentlicht 09.07.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in the Admin Console. An unauthentic...

  • EPSS 0.1%
  • Veröffentlicht 29.04.2025 00:00:00
  • Zuletzt bearbeitet 11.06.2025 21:20:21

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform u...

  • EPSS 0.16%
  • Veröffentlicht 19.12.2024 23:15:07
  • Zuletzt bearbeitet 11.06.2025 21:17:48

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive ...

  • EPSS 0.3%
  • Veröffentlicht 20.11.2024 19:15:06
  • Zuletzt bearbeitet 11.06.2025 21:16:54

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim...

  • EPSS 21.61%
  • Veröffentlicht 07.11.2024 21:15:06
  • Zuletzt bearbeitet 17.06.2025 18:41:30

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to i...