📦

zimbra_collaboration_suite

Vendor: synacor

Actively Exploited 17 CISA KEV List
PoC / Exploits 10 Code Available
Total RCEs 6 Remote Access
Total CVEs 443 Total Indexed
Avg. EPSS 19.23% Exploit Prob.
Latest CVE CVE-2026-33373 Mar 30

Security Vulnerability Index

Page 6 / 45
5.3 CVSS

Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.

EPSS: 0.61%
6.1 CVSS

Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.

EPSS: 1.59%
8.8 CVSS

Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.

EPSS: 6.22%
6.5 CVSS

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.

EPSS: 0.46%
5.3 CVSS

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump.

EPSS: 0.64%
5.3 CVSS

mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.

EPSS: 9.92%
6.1 CVSS

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

EPSS: 77.02%
5.4 CVSS

Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.

EPSS: 0.44%
6.1 CVSS

Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.

EPSS: 0.65%
6.1 CVSS

Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: 0.41%