VulnSea

zimbra_collaboration_suite vulnerabilities

CVEs whose affected-version data names the zimbra_collaboration_suite package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-73570High· 8.9CISA KEVPoC
1mo ago

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP …

Abyssalsynacor · zimbra_collaboration_suiteEPSS 32%via NVD
CVE-2022-41352Critical· 9.8CISA KEVPoC
3y ago

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to …

Hadalsynacor · zimbra_collaboration_suiteEPSS 95%via NVD
CVE-2022-37042Critical· 9.8CISA KEV0dayPoC
4y ago

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to t…

Hadalsynacor · zimbra_collaboration_suiteEPSS 92%via NVD
CVE-2022-27925High· 7.2CISA KEVPoC
4y ago

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, l…

Abyssalsynacor · zimbra_collaboration_suiteEPSS 99%via NVD
CVE-2022-27924High· 7.5CISA KEVPoC
4y ago

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

Abyssalsynacor · zimbra_collaboration_suiteEPSS 85%via NVD
CVE-2022-24682Medium· 6.1CISA KEV0dayPoC
4y ago

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript insi…

Midnightsynacor · zimbra_collaboration_suiteEPSS 31%via NVD
CVE-2018-6882Medium· 6.1CISA KEVPoC
8y ago

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…

Midnightsynacor · zimbra_collaboration_suiteEPSS 25%via NVD
zimbra_collaboration_suite vulnerabilities (CVEs) · VulnSea