Zimbra
zimbra
59 CVEs • 8 products
Products (8)
Click to collapseToggle
Products (8)
Click to collapse
CVEs (59)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker could place HTML containing executable JavaScript inside element attrib...Show more |
An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS vulnerability exists in the login component of Zimbra Web Client, in which an attacker can execute ar...Show more |
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth...Show more |
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra...Show more |
A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element con...Show more |
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account. This differs from the intended behavior in which the domain of the authenticated user m...Show more |
Zimbra 2013 has XSS in aspell.php |
1Zimbra 1Collaboration Server Nov 21, 2024 Jan 27, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS. |
1Zimbra 1Collaboration Server Nov 21, 2024 Jan 27, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS. |
1Zimbra 1Collaboration Server Nov 21, 2024 Jan 27, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS. |
1Zimbra 1Collaboration Server Nov 21, 2024 Jan 27, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability. |
Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console. |
2Synacor Zimbra2Zimbra Collaboration Suite Zimbra Collaboration SuiteNov 21, 2024 May 30, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group. |
2Synacor Zimbra2Zimbra Collaboration Suite Zimbra Collaboration SuiteNov 21, 2024 May 30, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hija...Show more |
1Zimbra 1Zimbra Collaboration Server May 6, 2026 Aug 29, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Zimbra 1Zimbra Collaboration Server May 6, 2026 Apr 8, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that ch...Show more |
Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a different vulnerability than CVE-2013-7091. |
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration Suite (ZCS) 4.0.3, 4.5.6, and possibly other versions before 4.5.10 allow remote attackers to inject arbitrary web script or HTML via an e-mail...Show more |