Zimbra
Zimbra Collaboration: vulnerabilidades y CVE
Zimbra Collaboration tiene 45 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE45
Últimos 12 meses2
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-27443 | Media (6.1) | 24% | ⚠ Explotación activa | 12 ago 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-67809 | Media (4.7) | 0.29% | — | 15 dic 2025 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are… |
| CVE-2025-62763 | Media (5) | 0.26% | — | 21 oct 2025 | Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy. |
| CVE-2025-54390 | Media (6.3) | 0.18% | — | 17 sept 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureResetPasswordStatus attribute is enabled. An attacker can exploit this… |
| CVE-2025-54391 | Crítica (9.1) | 0.62% | — | 16 sept 2025 | A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The attacker can… |
| CVE-2024-45515 | Media (6.1) | 0.30% | — | 30 jul 2025 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability exists in Zimbra webmail due to insufficient validation of the content type metadata when importing files… |
| CVE-2025-53645 | Alta (7.5) | 1.5% | — | 9 jul 2025 | Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive, comma-separated path segments in… |
| CVE-2025-27914 | Media (5.4) | 0.28% | — | 12 mar 2025 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute… |
| CVE-2024-45518 | Alta (8.8) | 21% | — | 22 oct 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery… |
| CVE-2024-33536 | Media (5.4) | 0.26% | — | 12 ago 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability occurs due to inadequate input validation of the res parameter, allowing an authenticated attacker to inject and execute arbitrary… |
| CVE-2024-33535 | Alta (7.5) | 0.55% | — | 12 ago 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting the handling of the packages… |
| CVE-2024-33533 | Media (5.4) | 0.28% | — | 12 ago 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0, issue 1 of 2. A reflected cross-site scripting (XSS) vulnerability has been identified in the Zimbra webmail admin interface. This vulnerability occurs… |
| CVE-2024-27443 | Media (6.1) | 24% | ⚠ Explotación activa | 12 ago 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input… |
| CVE-2024-27442 | Alta (7.8) | 0.35% | — | 12 ago 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the zimbra user with root privileges for specific mailbox operations.… |
| CVE-2023-50808 | Media (6.1) | 0.44% | — | 13 feb 2024 | Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI. |
| CVE-2023-48432 | Media (6.1) | 0.46% | — | 13 feb 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message,… |
| CVE-2023-45207 | Media (6.1) | 0.47% | — | 13 feb 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. While previewing this file in webmail in the Chrome… |
| CVE-2023-45206 | Media (6.1) | 0.41% | — | 13 feb 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS).… |
| CVE-2023-26562 | Media (6.5) | 0.58% | — | 13 feb 2024 | In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp. |
| CVE-2023-43103 | Media (6.1) | 0.49% | — | 7 dic 2023 | An XSS issue was discovered in a web endpoint in Zimbra Collaboration (ZCS) before 10.0.4 via an unsanitized parameter. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36. |
| CVE-2023-43102 | Media (6.1) | 0.49% | — | 7 dic 2023 | An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36. |
| CVE-2023-41106 | Alta (7.5) | 1.0% | — | 7 dic 2023 | An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42. |
| CVE-2023-34193 | Alta (8.8) | 1.2% | — | 6 jul 2023 | File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via the ClientUploader function. |
| CVE-2023-29382 | Crítica (9.8) | 1.0% | — | 6 jul 2023 | An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component. |
| CVE-2023-29381 | Crítica (9.8) | 1.0% | — | 6 jul 2023 | An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters. |
| CVE-2023-24032 | Alta (7.8) | 0.96% | — | 15 jun 2023 | In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege… |
| CVE-2023-24031 | Media (6.1) | 0.40% | — | 15 jun 2023 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 8.8.15. XSS can occur, via one of attributes of the webmail /h/ endpoint, to execute arbitrary JavaScript code, leading to information disclosure. |
| CVE-2023-24030 | Media (6.1) | 0.39% | — | 15 jun 2023 | An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a… |
| CVE-2022-45913 | Media (6.1) | 0.41% | — | 6 ene 2023 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execute arbitrary JavaScript code, leading to information disclosure. |
| CVE-2022-45911 | Media (6.1) | 0.41% | — | 6 ene 2023 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which… |
| CVE-2022-45912 | Alta (7.2) | 1.2% | — | 5 dic 2022 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.