Zimbra Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Zimbra products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

18

In CISA KEV

17

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

Zimbra KEVs Added by Year

Loading...

18 Zimbra KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-48700

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra...

Confirmed In CISA 01 Jun 2026
CVE-2025-66376

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import...

Confirmed In CISA 01 Jun 2026
CVE-2020-7796

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

Confirmed In CISA 28 May 2026
CVE-2025-68645

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper...

Confirmed In CISA 01 Jun 2026
CVE-2025-27915

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the...

Confirmed In CISA 01 Jun 2026
CVE-2019-9621

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows...

Confirmed In CISA 01 Jun 2026
CVE-2013-7091

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows...

High Not in CISA 05 Jun 2025
CVE-2024-27443

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature...

Confirmed In CISA 21 May 2025
CVE-2022-24682

An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild...

Confirmed In CISA 25 Feb 2022
CVE-2018-6882

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1...

Confirmed In CISA 19 Apr 2022
CVE-2022-27924

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance....

Confirmed In CISA 04 Aug 2022
CVE-2022-37042

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing...

Confirmed In CISA 11 Aug 2022
CVE-2022-27925

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated...

Confirmed In CISA 11 Aug 2022
CVE-2022-41352

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole...

Confirmed In CISA 20 Oct 2022
CVE-2022-27926

A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows...

Confirmed In CISA 03 Apr 2023
CVE-2023-37580

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

Confirmed In CISA 27 Jul 2023
CVE-2024-45519

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1...

Confirmed In CISA 03 Oct 2024
CVE-2023-34192

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to...

Confirmed In CISA 25 Feb 2025

Common Vulnerability Classes (CWE)

  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 8
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
  • CWE-918 — Server-Side Request Forgery (SSRF) 2
  • CWE-98 — Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
  • CWE-116 — Improper Encoding or Escaping of Output 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology