VulnSea

collaboration_suite_zcs vulnerabilities

CVEs whose affected-version data names the collaboration_suite_zcs package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-93642Critical· 9.3
today

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)via NVD
CVE-2026-93641Critical· 9.3
today

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)via NVD
CVE-2026-93643Critical· 9.8
today

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)via NVD
CVE-2026-93647Critical· 9.3
today

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)via NVD
collaboration_suite_zcs vulnerabilities (CVEs) · VulnSea