Showing 22 vulnerabilities on this page for Zimbra Collaboration Suite (ZCS)

Signals CISA KEV Ransomware Nuclei
Synacor vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

CWE-79Jan 5, 2026
CVSS7.2v3.1EPSS22%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

CWE-98Dec 22, 20251 related artifact
CVSS8.8v3.1EPSS31.8%PoCs7SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vecto

CWE-79Jun 23, 2025
CVSS6.1v3.1EPSS1.76%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a <details> tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions suc

CWE-79Mar 12, 20251 related artifact
CVSS5.4v3.1EPSS3.92%PoCs0SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is reflected back in the HTML response.

CWE-79Nov 7, 2024
CVSS6.1v3.1EPSS61.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

CWE-284CWE-78CWE-863Oct 2, 20241 related artifact
CVSS10.0v3.1EPSS99.9%PoCs3SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context

CWE-79Aug 12, 20241 related artifact
CVSS6.1v3.1EPSS23.6%PoCs0SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

CWE-79Jul 31, 20231 related artifact
CVSS6.1v3.1EPSS46.7%PoCs0SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

CWE-79Jul 6, 20231 related artifact
CVSS9.0v3.1EPSS77.3%PoCs0SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Zimbra sudo + postfix privilege escalation

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

CWE-269CWE-271Oct 17, 2022
CVSS7.8v3.1EPSS0.715%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it ov

CWE-22CWE-434Sep 26, 20221 related artifact
CVSS9.8v3.1EPSS95.5%PoCs5SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

CWE-22CWE-23CWE-287Aug 11, 20221 related artifact
CVSS9.8v3.1EPSS91.9%PoCs4SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters.

CWE-138CWE-79Apr 20, 20221 related artifact
CVSS6.1v3.1EPSS17.6%PoCs0SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

CWE-22CWE-434Apr 20, 2022
CVSS7.2v3.1EPSS98.6%PoCs12SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

CWE-74CWE-77CWE-93Apr 20, 20221 related artifact
CVSS7.5v3.1EPSS85.4%PoCs0SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.

CWE-116CWE-79Feb 9, 20221 related artifact
CVSS6.1v3.1EPSS30.9%PoCs0SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

CWE-918Feb 18, 20202 related artifacts
CVSS9.8v3.1EPSS84.4%PoCs0SignalsListed in CISA KEVNo known ransomware use2 Nuclei templatesSTIX

Synacor Zimbra Collaboration Suite (ZCS) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.

CWE-79May 29, 20191 related artifact
CVSS6.1v3.0EPSS7.44%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

CWE-611May 29, 20191 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs4SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

CWE-807CWE-918Apr 30, 20191 related artifact
CVSS7.5v3.1EPSS81%PoCs4SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

CWE-79Mar 27, 20181 related artifact
CVSS6.1v3.1EPSS25.4%PoCs0SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Synacor Zimbra Collaboration Suite (ZCS) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

CWE-22Dec 13, 20131 related artifact
CVSS5.0v2.0EPSS86.3%PoCs3SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX