CVE-2026-93647
- EPSS 0.23%
- Veröffentlicht 25.09.2026 13:58:05
- Zuletzt bearbeitet 29.09.2026 21:29:07
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
CVE-2026-93643
- EPSS 0.96%
- Veröffentlicht 25.09.2026 13:57:19
- Zuletzt bearbeitet 29.09.2026 21:29:07
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
CVE-2026-93642
- EPSS 0.23%
- Veröffentlicht 25.09.2026 13:56:04
- Zuletzt bearbeitet 29.09.2026 21:29:07
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
CVE-2026-93641
- EPSS 0.27%
- Veröffentlicht 25.09.2026 13:55:10
- Zuletzt bearbeitet 29.09.2026 21:29:07
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
CVE-2025-71275
- EPSS 0.46%
- Veröffentlicht 24.03.2026 15:21:05
- Zuletzt bearbeitet 25.03.2026 16:16:08
Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519.
CVE-2026-33368
- EPSS 0.22%
- Veröffentlicht 20.03.2026 14:16:15
- Zuletzt bearbeitet 01.04.2026 15:37:25
Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanitize user-supplied input, allowing an unauthenticated ...
CVE-2025-54390
- EPSS 0.18%
- Veröffentlicht 17.09.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureResetPasswordStatus attribute is enabled. An attacker can exploit this by tricking an authenticated use...
CVE-2025-54391
- EPSS 0.62%
- Veröffentlicht 16.09.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can configure an additional 2FA method (ei...
CVE-2024-45515
- EPSS 0.29%
- Veröffentlicht 30.07.2025 00:00:00
- Zuletzt bearbeitet 07.08.2025 18:16:45
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can...
CVE-2025-53645
- EPSS 1.4%
- Veröffentlicht 09.07.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in the Admin Console. An unauthentic...