📦 Collaboration

by Zimbra

🔍 What is Collaboration?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-29381

CRITICAL CVSS 9.8 Jul 6, 2023

This vulnerability in Zimbra Collaboration Suite allows remote attackers to bypass authentication mechanisms and escalate privileges by exploiting flaws in password and two-factor authentication param...

CVE-2022-32294

CRITICAL CVSS 9.8 Jul 11, 2022

Zimbra Collaboration Open Source 8.8.15 logs randomly generated initial login passwords in cleartext via syslog on UDP port 514. This allows attackers with network access to intercept these temporary ...

CVE-2024-45518

HIGH CVSS 8.8 Oct 22, 2024

This vulnerability in Zimbra Collaboration allows authenticated users to perform Server-Side Request Forgery (SSRF) attacks due to improper input sanitization and domain whitelisting misconfigurations...

CVE-2024-27442

HIGH CVSS 7.8 Aug 12, 2024

This vulnerability allows local privilege escalation in Zimbra Collaboration Suite. An attacker with access to the zimbra user account can exploit improper input handling in the zmmailboxdmgr binary t...

CVE-2024-33535

HIGH CVSS 7.5 Aug 12, 2024

This vulnerability allows unauthenticated attackers to read arbitrary files from a specific directory in Zimbra Collaboration Suite. It affects Zimbra Collaboration (ZCS) versions 9.0 and 10.0 through...

CVE-2023-41106

HIGH CVSS 7.5 Dec 7, 2023

This vulnerability in Zimbra Collaboration Suite allows attackers to gain unauthorized access to Zimbra user accounts. It affects Zimbra installations running vulnerable versions before the patched re...

CVE-2023-34193

HIGH CVSS 8.8 Jul 6, 2023

This vulnerability allows authenticated privileged users in Zimbra Collaboration Suite to upload malicious files through the ClientUploader function, potentially leading to remote code execution and s...

CVE-2023-24032

HIGH CVSS 7.8 Jun 15, 2023

This vulnerability allows an attacker with initial user access to a Zimbra Collaboration Suite server to execute arbitrary commands as root by manipulating JVM arguments, leading to local privilege es...

CVE-2025-67809

MEDIUM CVSS 4.7 Dec 15, 2025

Zimbra Collaboration 10.0 and 10.1 contain hardcoded Flickr API credentials in the publicly accessible Flickr Zimlet. Attackers can retrieve these credentials and impersonate the legitimate applicatio...

CVE-2024-45515

MEDIUM CVSS 6.1 Jul 30, 2025

This Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration allows attackers to upload specially crafted files that bypass content type validation, enabling execution of arbitrary JavaScript...

CVE-2024-33533

MEDIUM CVSS 5.4 Aug 12, 2024

This reflected XSS vulnerability in Zimbra Collaboration allows authenticated attackers to inject malicious JavaScript via the packages parameter in the admin interface. When another user visits a cra...