Zarafa is a modestly represented collaboration and messaging platform vendor with a narrow product portfolio centered on its Zarafa Collaboration Platform, WebAccess, and web applications, serving as a groupware alternative to larger enterprise platforms. The vendor's vulnerability surface recurs through information-disclosure exposures, input-validation weaknesses, link-following issues in file handling, and cross-site scripting flaws—attack vectors characteristic of web-facing messaging and calendar services where data sensitivity and user-supplied content handling are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zarafa over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7219MEDIUM Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Weba | Apr 11, 2019 | 6.1 | 26 | NO | YES |
CVE-2021-28994HIGH kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows m | Mar 31, 2021 | 7.5 | 21 | NO | NO |
CVE-2015-6566HIGH zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*. | Jan 11, 2016 | 8.4 | 21 | NO | NO |
CVE-2014-9465MEDIUM senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attack | Feb 19, 2015 | 5.0 | 21 | NO | NO |
CVE-2014-5450MEDIUM Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information by reading license files. | Mar 19, 2018 | 5.5 | 20 | NO | NO |
CVE-2014-0037MEDIUM The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of service (crash) via vectors relate | Apr 28, 2014 | 5.0 | 19 | NO | NO |
CVE-2015-3436MEDIUM provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp | Jun 9, 2015 | 6.6 | 17 | NO | NO |
CVE-2014-0079MEDIUM The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a den | Apr 28, 2014 | 5.0 | 15 | NO | NO |
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary | Oct 20, 2014 | 2.1 | 13 | NO | NO |
Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by reading the log files. | Oct 20, 2014 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zarafa.
Media articles that mention a CVE ID that affects a product developed by Zarafa — matched by CVE ID, not by vendor name.