Zimbra Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Zimbra products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
18
In CISA KEV
17
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Zimbra KEVs Added by Year
18 Zimbra KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-48700
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra... |
Zimbra Collaboration (ZCS) | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-66376
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import... |
Collaboration | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-7796
Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. |
Zimbra Collaboration Suite | Confirmed | In CISA | 28 May 2026 |
|
CVE-2025-68645
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper... |
Zimbra Collaboration (ZCS) | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-27915
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the... |
Zimbra Collaboration (ZCS) | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2019-9621
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows... |
Zimbra Collaboration Suite | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2013-7091
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows... |
Zimbra Collaboration Suite | High | Not in CISA | 05 Jun 2025 |
|
CVE-2024-27443
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature... |
Zimbra Collaboration (ZCS) | Confirmed | In CISA | 21 May 2025 |
|
CVE-2022-24682
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild... |
Collaboration Suite | Confirmed | In CISA | 25 Feb 2022 |
|
CVE-2018-6882
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1... |
Collaboration Suite | Confirmed | In CISA | 19 Apr 2022 |
|
CVE-2022-27924
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance.... |
Zimbra Collaboration | Confirmed | In CISA | 04 Aug 2022 |
|
CVE-2022-37042
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing... |
Collaboration Suite | Confirmed | In CISA | 11 Aug 2022 |
|
CVE-2022-27925
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated... |
Collaboration | Confirmed | In CISA | 11 Aug 2022 |
|
CVE-2022-41352
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole... |
Collaboration | Confirmed | In CISA | 20 Oct 2022 |
|
CVE-2022-27926
A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows... |
Collaboration | Confirmed | In CISA | 03 Apr 2023 |
|
CVE-2023-37580
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. |
Zimbra Collaboration | Confirmed | In CISA | 27 Jul 2023 |
|
CVE-2024-45519
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1... |
Zimbra Collaboration | Confirmed | In CISA | 03 Oct 2024 |
|
CVE-2023-34192
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to... |
Zimbra Collaboration Suite | Confirmed | In CISA | 25 Feb 2025 |
Common Vulnerability Classes (CWE)
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 8
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
- CWE-918 — Server-Side Request Forgery (SSRF) 2
- CWE-98 — Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
- CWE-116 — Improper Encoding or Escaping of Output 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology