📦 Zimbra Collaboration Suite

by Synacor

🔍 What is Zimbra Collaboration Suite?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-45519

CRITICAL CVSS 10.0 Oct 2, 2024

This critical vulnerability in Zimbra Collaboration's postjournal service allows unauthenticated attackers to execute arbitrary commands on affected systems. All Zimbra Collaboration deployments runni...

CVE-2020-7796

CRITICAL CVSS 9.8 Feb 18, 2020

This vulnerability in Zimbra Collaboration Suite allows Server-Side Request Forgery (SSRF) when the WebEx zimlet is installed and JSP functionality is enabled. Attackers can exploit this to make unaut...

CVE-2025-68645

HIGH CVSS 8.8 Dec 22, 2025

An unauthenticated remote attacker can exploit this Local File Inclusion vulnerability in Zimbra Collaboration's Webmail Classic UI to read arbitrary files from the WebRoot directory. This affects Zim...

CVE-2025-32354

HIGH CVSS 8.8 Apr 29, 2025

A Cross-Site Request Forgery vulnerability in Zimbra Collaboration's GraphQL endpoint allows attackers to perform unauthorized operations when authenticated users visit malicious websites. This affect...

CVE-2025-25064

HIGH CVSS 8.8 Feb 3, 2025

This SQL injection vulnerability in Zimbra Collaboration's ZimbraSync Service SOAP endpoint allows authenticated attackers to inject arbitrary SQL queries by manipulating a specific parameter. Exploit...

CVE-2024-54663

HIGH CVSS 7.5 Dec 19, 2024

This CVE describes a Local File Inclusion vulnerability in Zimbra Collaboration's Webmail Classic UI. Authenticated attackers can access sensitive files in the WebRoot directory by crafting malicious ...

CVE-2022-27924

HIGH CVSS 7.5 Apr 21, 2022

CVE-2022-27924 is an unauthenticated memcache command injection vulnerability in Zimbra Collaboration Suite. It allows attackers to overwrite arbitrary cached entries, potentially leading to authentic...

CVE-2025-48700

MEDIUM CVSS 6.1 Jun 23, 2025

A Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration's Classic UI allows attackers to execute arbitrary JavaScript in users' sessions by sending specially crafted emails. This can lead t...

CVE-2024-45516

MEDIUM CVSS 6.1 May 14, 2025

A Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration's Classic UI allows attackers to execute arbitrary JavaScript when users view specially crafted emails. This can lead to session hija...

CVE-2025-27915

MEDIUM CVSS 5.4 Mar 12, 2025

This stored XSS vulnerability in Zimbra Collaboration allows attackers to inject malicious JavaScript via ICS calendar files in emails. When victims view these emails, the JavaScript executes in their...

CVE-2025-25065

MEDIUM CVSS 5.3 Feb 3, 2025

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration's RSS feed parser. It allows attackers to redirect requests to internal network endpoints, potentially acc...

CVE-2024-45194

MEDIUM CVSS 4.8 Nov 21, 2024

This stored XSS vulnerability in Zimbra Collaboration allows attackers with administrative access to inject malicious JavaScript into email account configurations. The injected code executes in victim...

CVE-2024-45517

MEDIUM CVSS 5.4 Nov 21, 2024

This Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration allows attackers to execute arbitrary JavaScript in victim sessions by exploiting improper input sanitization in the /h/rest endpo...

CVE-2024-45514

MEDIUM CVSS 5.4 Nov 21, 2024

This CVE describes a Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration (ZCS) webmail where attackers can inject malicious JavaScript via the packages parameter. The vulnerability affect...

CVE-2024-45510

MEDIUM CVSS 5.4 Nov 20, 2024

This stored XSS vulnerability in Zimbra Collaboration allows attackers to inject malicious JavaScript into email fields. When victims add attacker-controlled contacts, the code executes in their webma...

CVE-2024-50599

MEDIUM CVSS 6.1 Nov 7, 2024

A reflected Cross-Site Scripting vulnerability in Zimbra Collaboration Suite 8.8.15 allows attackers to inject malicious scripts via webmail calendar endpoints. When exploited, this can lead to sessio...