Vulnerabilities > Zimbra

DATE CVE VULNERABILITY TITLE RISK
2020-12-17 CVE-2020-35123 XXE vulnerability in Zimbra Collaboration 8.8.15/9.0.0
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks.
network
low complexity
zimbra CWE-611
4.0
2020-05-05 CVE-2020-11737 Cross-Site Scripting vulnerability in Zimbra 9.0.0
A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript.
network
zimbra CWE-79
4.3
2020-03-20 CVE-2020-10194 Incorrect Authorization vulnerability in Zimbra Zm-Mailbox
cs/service/account/AutoCompleteGal.java in Zimbra zm-mailbox before 8.8.15.p8 allows authenticated users to request any GAL account.
network
low complexity
zimbra CWE-863
4.0
2020-02-12 CVE-2013-1938 Cross-Site Scripting vulnerability in Zimbra 2013
Zimbra 2013 has XSS in aspell.php
network
zimbra CWE-79
4.3
2020-01-27 CVE-2019-8947 Cross-Site Scripting vulnerability in Zimbra Collaboration Server
Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.
network
zimbra CWE-79
4.3
2020-01-27 CVE-2019-8946 Cross-Site Scripting vulnerability in Zimbra Collaboration Server
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
network
zimbra CWE-79
4.3
2020-01-27 CVE-2019-8945 Cross-Site Scripting vulnerability in Zimbra Collaboration Server
Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.
network
zimbra CWE-79
4.3
2020-01-27 CVE-2019-15313 Cross-Site Scripting vulnerability in Zimbra Collaboration Server
In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.
network
zimbra CWE-79
4.3
2020-01-27 CVE-2019-12427 Cross-Site Scripting vulnerability in Zimbra Collaboration Server
Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.
network
zimbra CWE-79
3.5
2019-04-30 CVE-2019-9621 Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration Server
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
network
low complexity
zimbra CWE-918
5.0