Synacor Vulnerabilities and Affected Products
Vulnerabilities associated with Zimbra Collaboration Suite (ZCS).
Products
Clear product- Zimbra Collaboration Suite (ZCS)22 vulnerabilities
- Zimbra Collaborate Suite (ZCS)1 vulnerability
- Zimbra Collaboration Suite1 vulnerability
- Zimbra Server1 vulnerability
- zimbra_collaboration_suite1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-66376HIGH | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting VulnerabilityZimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. CWE-79Jan 5, 2026 | CVSS7.2v3.1 | EPSS22% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68645HIGH | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion VulnerabilityA Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory. | CVSS8.8v3.1 | EPSS31.8% | PoCs7 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-48700MEDIUM | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting VulnerabilityAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vecto… CWE-79Jun 23, 2025 | CVSS6.1v3.1 | EPSS1.76% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27915MEDIUM | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting VulnerabilityAn issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions suc… | CVSS5.4v3.1 | EPSS3.92% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-50599MEDIUM | Synacor Zimbra Collaboration Suite (ZCS) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is reflected back in the HTML response. CWE-79Nov 7, 2024 | CVSS6.1v3.1 | EPSS61.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45519CRITICAL | Synacor Zimbra Collaboration Suite (ZCS) Command Execution VulnerabilityThe postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands. | CVSS10.0v3.1 | EPSS99.9% | PoCs3 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-27443MEDIUM | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityAn issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context… | CVSS6.1v3.1 | EPSS23.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-37580MEDIUM | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityZimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. | CVSS6.1v3.1 | EPSS46.7% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-34192CRITICAL | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityCross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. | CVSS9.0v3.1 | EPSS77.3% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-3569HIGH | Zimbra sudo + postfix privilege escalationDue to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'. | CVSS7.8v3.1 | EPSS0.715% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41352CRITICAL | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it ov… | CVSS9.8v3.1 | EPSS95.5% | PoCs5 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2022-37042CRITICAL | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass VulnerabilityZimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925. | CVSS9.8v3.1 | EPSS91.9% | PoCs4 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2022-27926MEDIUM | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityA reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters. | CVSS6.1v3.1 | EPSS17.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-27925HIGH | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityZimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal. | CVSS7.2v3.1 | EPSS98.6% | PoCs12 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2022-27924HIGH | Synacor Zimbra Collaboration Suite (ZCS) Command Injection VulnerabilityZimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries. | CVSS7.5v3.1 | EPSS85.4% | PoCs0 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2022-24682MEDIUM | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting VulnerabilityAn issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document. | CVSS6.1v3.1 | EPSS30.9% | PoCs0 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2020-7796CRITICAL | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery VulnerabilityZimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. | CVSS9.8v3.1 | EPSS84.4% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use2 Nuclei templates | STIX |
CVE-2018-14013MEDIUM | Synacor Zimbra Collaboration Suite (ZCS) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. | CVSS6.1v3.0 | EPSS7.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-9670CRITICAL | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Referencemailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml. | CVSS9.8v3.1 | EPSS>99.9% | PoCs4 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-9621HIGH | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) VulnerabilityZimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component. | CVSS7.5v3.1 | EPSS81% | PoCs4 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-6882MEDIUM | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) VulnerabilityCross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment. | CVSS6.1v3.1 | EPSS25.4% | PoCs0 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
Synacor Zimbra Collaboration Suite (ZCS) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API. | CVSS5.0v2.0 | EPSS86.3% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |