← Back

Synacor

synacor

94 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (94)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
May 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
1Synacor
1Zimbra Collaboration Suite
Jun 17, 2026
Apr 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
Oct 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
2Synacor
Zimbra
2Zimbra Collaboration Suite
Zimbra Collaboration Suite
Nov 21, 2024
May 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
2Synacor
Zimbra
2Zimbra Collaboration Suite
Zimbra Collaboration Suite
Nov 21, 2024
May 30, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hija...Show more
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.Show less
1Synacor
1Zimbra Collaboration Suite
Aug 15, 2025
May 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Ad...Show more
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.Show less
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
May 10, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full us...Show more
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump.Show less
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
May 10, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authen...Show more
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.Show less
1Synacor
1Zimbra Collaboration Suite
Aug 13, 2026
Mar 27, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary...Show more
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.Show less
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
Feb 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.
1Synacor
1Zimbra Collaboration Suite
Nov 21, 2024
Feb 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
May 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors.
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
May 17, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging failure to use of a CSRF token and perform referer header checks, aka bugs 100885 and 100899.Show less
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
Mar 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
Jan 18, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 104477.
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
Jan 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703.
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
Jan 18, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.
1Synacor
1Zimbra Collaboration Suite
May 13, 2026
Jan 18, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Zimbra Collaboration before 8.6.0 Patch 7 allows remote authenticated users to affect availability via unknown vectors, aka bug 102029.