Zimbra operates a unified messaging and collaboration platform—email, calendar, contacts, and document sharing—deployed across enterprises and service providers as an on-premises or cloud solution. Despite a narrowly focused product line, the platform's prevalence in critical communication infrastructure and its internet-facing attack surface place it among more prominent vendors in the vulnerability landscape. Vulnerabilities affecting Zimbra cluster around web-application weaknesses, notably cross-site scripting, cross-site request forgery, server-side request forgery, and code injection, reflecting the complexity of a rich web interface handling user input and inter-component communication. The exposure reaches moderate severity levels, and a meaningful share has acquired public exploit code, making disclosures in this product line relevant to defenders managing email and collaboration deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zimbra over time
Signals from CVEs in this vendor scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27443MEDIUM An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic us | Aug 12, 2024 | 6.1 | 80 | YES | YES |
CVE-2025-66376MEDIUM Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. | Jan 5, 2026 | 6.1 | 74 | YES | NO |
CVE-2022-37393HIGH Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user- | Aug 16, 2022 | 7.8 | 36 | NO | YES |
CVE-2024-45518HIGH An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users t | Oct 22, 2024 | 8.8 | 35 | NO | NO |
CVE-2015-6541HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication | Apr 8, 2016 | 8.8 | 32 | NO | YES |
CVE-2022-32294CRITICAL Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (ak | Jul 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-35209CRITICAL An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.x before 9.0.0 Patch 16. The value of the X-Host h | Jul 2, 2021 | 9.8 | 31 | NO | NO |
CVE-2013-7217HIGH Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a different vulnerability than C | Dec 26, 2013 | 10.0 | 31 | NO | NO |
CVE-2023-29382CRITICAL An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component. | Jul 6, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-29381CRITICAL An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters. | Jul 6, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (61 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zimbra.
Media articles that mention a CVE ID that affects a product developed by Zimbra — matched by CVE ID, not by vendor name.