Zimbra

Collaboration

69 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 20.03.2026 14:16:16
  • Zuletzt bearbeitet 01.04.2026 15:36:22

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient sanitization of specific uploaded file types. When a user opens a public...

  • EPSS 0.23%
  • Veröffentlicht 20.03.2026 14:16:16
  • Zuletzt bearbeitet 01.04.2026 15:36:59

Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search ...

Warnung Medienbericht
  • EPSS 21.97%
  • Veröffentlicht 05.01.2026 00:00:00
  • Zuletzt bearbeitet 18.03.2026 20:13:37

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Warnung Medienbericht
  • EPSS 34.44%
  • Veröffentlicht 22.12.2025 18:16:17
  • Zuletzt bearbeitet 23.01.2026 18:39:33

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can...

  • EPSS 0.29%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 30.12.2025 20:30:14

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimle...

  • EPSS 0.24%
  • Veröffentlicht 21.10.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

  • EPSS 0.29%
  • Veröffentlicht 30.07.2025 00:00:00
  • Zuletzt bearbeitet 07.08.2025 18:16:45

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files into the briefcase. Attackers can...

Warnung Medienbericht
  • EPSS 1.76%
  • Veröffentlicht 23.06.2025 00:00:00
  • Zuletzt bearbeitet 21.04.2026 12:48:23

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leadin...

  • EPSS 0.41%
  • Veröffentlicht 14.05.2025 00:00:00
  • Zuletzt bearbeitet 11.06.2025 21:20:29

An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbi...

Warnung Medienbericht Exploit
  • EPSS 3.92%
  • Veröffentlicht 12.03.2025 00:00:00
  • Zuletzt bearbeitet 04.11.2025 16:45:11

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail...