Record summary

CVE-2025-66376 has a selected CVSS score of 7.2 (high). CISA lists CVE-2025-66376 in KEV.

Description

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 18, 2026 · CISA
VulnCheck KEV
Listed · Mar 17, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 17, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Default status: unaffected

CVE List10.0 to < 10.0.18affected
10.1 to < 10.1.13affected

References

7