Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zarafa

First CVE: Apr 28, 2014Active for: 12 yearsTotal CVEs: 12
23.2
VTI Score
Low

Zarafa is a modestly represented collaboration and messaging platform vendor with a narrow product portfolio centered on its Zarafa Collaboration Platform, WebAccess, and web applications, serving as a groupware alternative to larger enterprise platforms. The vendor's vulnerability surface recurs through information-disclosure exposures, input-validation weaknesses, link-following issues in file handling, and cross-site scripting flaws—attack vectors characteristic of web-facing messaging and calendar services where data sensitivity and user-supplied content handling are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
4.8
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zarafa over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 28, 2014
12 years ago
Most Recent CVE
Mar 31, 2021
1,941 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-7219MEDIUM
Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Weba
Apr 11, 20196.126NOYES
CVE-2021-28994HIGH
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows m
Mar 31, 20217.521NONO
CVE-2015-6566HIGH
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.
Jan 11, 20168.421NONO
CVE-2014-9465MEDIUM
senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attack
Feb 19, 20155.021NONO
CVE-2014-5450MEDIUM
Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information by reading license files.
Mar 19, 20185.520NONO
CVE-2014-0037MEDIUM
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of service (crash) via vectors relate
Apr 28, 20145.019NONO
CVE-2015-3436MEDIUM
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp
Jun 9, 20156.617NONO
CVE-2014-0079MEDIUM
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a den
Apr 28, 20145.015NONO
CVE-2014-5449LOW
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary
Oct 20, 20142.113NONO
CVE-2014-5448LOW
Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by reading the log files.
Oct 20, 20142.113NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
33%
50%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (16.7%)
Network2 (16.7%)
Unknown8 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (33.3%)
High0 (0.0%)
Unknown8 (66.7%)
User Interaction
None3 (25.0%)
Unknown8 (66.7%)
Required1 (8.3%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None3 (25.0%)
Unknown8 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zarafa.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zarafa — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zarafa's Products

View all 2 CNAs →

Top CWEs