Zimbra ZCS 10 <10.0.18 / 10.1 <10.1.13 Classic UI XSS via CSS @import
CVE-2025-66376 Published on January 5, 2026

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

NVD

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2025-66376 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2025-66376

Want to know whenever a new CVE is published for Zimbra Collaboration? stack.watch will email you.

 

Affected Versions

Zimbra Collaboration:

Exploit Probability

EPSS
0.05%
Percentile
14.40%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.