Zimbra

Zimbra Collaboration Suite

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 25.09.2026 13:58:05
  • Zuletzt bearbeitet 29.09.2026 21:29:07

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

  • EPSS 0.96%
  • Veröffentlicht 25.09.2026 13:57:19
  • Zuletzt bearbeitet 29.09.2026 21:29:07

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

  • EPSS 0.23%
  • Veröffentlicht 25.09.2026 13:56:04
  • Zuletzt bearbeitet 29.09.2026 21:29:07

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

  • EPSS 0.27%
  • Veröffentlicht 25.09.2026 13:55:10
  • Zuletzt bearbeitet 29.09.2026 21:29:07

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 24.03.2026 15:21:05
  • Zuletzt bearbeitet 25.03.2026 16:16:08

Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519.

  • EPSS 0.22%
  • Veröffentlicht 20.03.2026 14:16:15
  • Zuletzt bearbeitet 01.04.2026 15:37:25

Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanitize user-supplied input, allowing an unauthenticated ...

  • EPSS 0.18%
  • Veröffentlicht 17.09.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureResetPasswordStatus attribute is enabled. An attacker can exploit this by tricking an authenticated use...

  • EPSS 0.62%
  • Veröffentlicht 16.09.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (ei...

  • EPSS 0.29%
  • Veröffentlicht 30.07.2025 00:00:00
  • Zuletzt bearbeitet 07.08.2025 18:16:45

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can...

  • EPSS 1.4%
  • Veröffentlicht 09.07.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in the Admin Console. An unauthentic...