Vulnerabilidades em Zimbra
13 resultadosAnálise Vexday
Zimbra apresenta 6 vulnerabilidades registradas, com 1 sob ataque ativo (KEV), todas em severidade abaixo de crítica. A fraqueza dominante é Cross-Site Scripting (CWE-79), e não há divulgações recentes nos últimos 90 dias, indicando um risco estável mas monitorado pela presença de exploração em campo.
CVE-2026-73570HIGHA remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installedEPSS 20.5%KEVCVE-2025-66376HIGHZimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import dEPSS 19.3%KEVCVE-2013-1938—Zimbra 2013 has XSS in aspell.phpEPSS 3.3%CVE-2017-20191LOWZimbra zm-admin-ajax Form Textbox Field Error XFormItem.js XFormItem.prototype.setError cross site scriptingEPSS 0.5%CVE-2024-9665MEDIUMZimbra GraphQL Cross-Site Request Forgery Information Disclosure VulnerabilityEPSS 0.5%CVE-2017-20188LOWZimbra zm-ajax XFormItem.js XFormItem.prototype.setError cross site scriptingEPSS 0.4%CVE-2026-73573LOWIn Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality dEPSS 0.3%CVE-2025-62763MEDIUMZimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.EPSS 0.2%CVE-2026-73574LOWIn Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper vEPSS 0.2%CVE-2026-73576MEDIUMIn Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbEPSS 0.2%CVE-2026-73571LOWAn authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegaEPSS 0.2%CVE-2026-73572MEDIUMIn Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due EPSS 0.2%CVE-2026-73575LOWIn Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) enEPSS 0.1%