Zimbra Zimbra

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Zimbra.

By the Year

In 2025 there have been 0 vulnerabilities in Zimbra. Last year, in 2024 Zimbra had 1 security vulnerability published. Right now, Zimbra is on track to have less security vulnerabilities in 2025 than it did last year.

Year Vulnerabilities Average Score
2025 0 0.00
2024 1 6.50
2023 2 6.80
2022 0 0.00
2021 0 0.00
2020 1 6.10

It may take a day or so for new Zimbra vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Zimbra Security Vulnerabilities

Zimbra GraphQL CSRF Info Disclosure via Malicious Email
CVE-2024-9665 6.5 - Medium - November 22, 2024

Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Zimbra. User interaction is required to exploit this vulnerability in that the target must open a malicious email message. The specific flaw exists within the implementation of the graphql endpoint. The issue results from the lack of proper protections against cross-site request forgery (CSRF) attacks. An attacker can leverage this vulnerability to disclose information in the context of the target email account. Was ZDI-CAN-23939.

Session Riding

In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files
CVE-2023-38750 7.5 - High - July 31, 2023

In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed.

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41
CVE-2023-37580 6.1 - Medium - July 31, 2023

Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

XSS

A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0
CVE-2020-11737 6.1 - Medium - May 05, 2020

A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element containing an href attribute with a "www" substring (including the quotes) followed immediately by a DOM event listener such as onmouseover. This is fixed in 9.0.0 Patch 2.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Zimbra or by Zimbra? Click the Watch button to subscribe.

Zimbra
Vendor

Zimbra
Product

subscribe