CVE-2025-66376High· 7.2▾ Abyssal⚠ Exploited in the wildZimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 39.6 · likelihood 3.9 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Apr 1, 2026
Last analysed / modified upstream
20%
Added to the CISA catalog on Mar 18, 2026. Federal remediation due Apr 1, 2026. View catalog ↗
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
zimbra_collaboration_suite >= 10.0.0, < 10.0.18zimbra_collaboration_suite >= 10.1.0, < 10.1.13Upgrade past the affected range:
zimbra_collaboration_suite 10.1.13Connected by shared product, vendor, weakness, or advisory.
CVE-2018-6882Medium· 6.1Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…
CVE-2022-41352Critical· 9.8An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0
CVE-2022-24682Medium· 6.1An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021
CVE-2022-37042Critical· 9.8Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it
CVE-2022-27925High· 7.2Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it
CVE-2022-27924High· 7.5Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance