Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zimbra

First CVE: Mar 10, 2008Active for: 18 yearsTotal CVEs: 61
51.0
VTI Score
TOP TARGET

Zimbra operates a unified messaging and collaboration platform—email, calendar, contacts, and document sharing—deployed across enterprises and service providers as an on-premises or cloud solution. Despite a narrowly focused product line, the platform's prevalence in critical communication infrastructure and its internet-facing attack surface place it among more prominent vendors in the vulnerability landscape. Vulnerabilities affecting Zimbra cluster around web-application weaknesses, notably cross-site scripting, cross-site request forgery, server-side request forgery, and code injection, reflecting the complexity of a rich web interface handling user input and inter-component communication. The exposure reaches moderate severity levels, and a meaningful share has acquired public exploit code, making disclosures in this product line relevant to defenders managing email and collaboration deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
61
Total CVEs
More Total CVEs than 99% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
3.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Zimbra over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2008
18 years ago
Most Recent CVE
Jan 5, 2026
200 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (61 CVEs).

61 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-27443MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic us
Aug 12, 20246.180YESYES
CVE-2025-66376MEDIUM
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Jan 5, 20266.174YESNO
CVE-2022-37393HIGH
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-
Aug 16, 20227.836NOYES
CVE-2024-45518HIGH
An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users t
Oct 22, 20248.835NONO
CVE-2015-6541HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication
Apr 8, 20168.832NOYES
CVE-2022-32294CRITICAL
Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (ak
Jul 11, 20229.831NONO
CVE-2021-35209CRITICAL
An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host h
Jul 2, 20219.831NONO
CVE-2013-7217HIGH
Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a different vulnerability than C
Dec 26, 201310.031NONO
CVE-2023-29382CRITICAL
An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.
Jul 6, 20239.827NONO
CVE-2023-29381CRITICAL
An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.
Jul 6, 20239.826NONO
View all 61 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products61 CVEs
70%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (6.6%)
Network54 (88.5%)
Unknown3 (4.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low56 (91.8%)
High2 (3.3%)
Unknown3 (4.9%)
User Interaction
None19 (31.1%)
Unknown3 (4.9%)
Required39 (63.9%)
Privileges Required
Low15 (24.6%)
High2 (3.3%)
None41 (67.2%)
Unknown3 (4.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (61 CVEs).

CISA KEV
2 CVEs
3.3% of CVEs· 99th percentile
Metasploit
1 CVE
1.6% of CVEs· 97th percentile
Nuclei
1 CVE
1.6% of CVEs· 95th percentile
ExploitDB
3 CVEs
4.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zimbra.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zimbra — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zimbra's Products

View all 5 CNAs →

Top CWEs