Vulnerabilities > Zimbra > Zimbra > 9.0.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-22 | CVE-2024-9665 | Cross-Site Request Forgery (CSRF) vulnerability in Zimbra Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability. | 6.5 |
2023-07-31 | CVE-2023-38750 | Unspecified vulnerability in Zimbra In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed. | 7.5 |
2020-05-05 | CVE-2020-11737 | Cross-site Scripting vulnerability in Zimbra 9.0.0 A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. | 6.1 |