Vulnerabilities (CVE)

Filtered by vendor Zimbra Subscribe
Filtered by product Zimbra
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37580 1 Zimbra 1 Zimbra 2023-12-22 N/A 6.1 MEDIUM
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
CVE-2020-11737 1 Zimbra 1 Zimbra 2020-05-07 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Web Client in Zimbra 9.0 allows a remote attacker to craft links in an E-Mail message or calendar invite to execute arbitrary JavaScript. The attack requires an A element containing an href attribute with a "www" substring (including the quotes) followed immediately by a DOM event listener such as onmouseover. This is fixed in 9.0.0 Patch 2.
CVE-2013-1938 1 Zimbra 1 Zimbra 2020-02-25 4.3 MEDIUM 6.1 MEDIUM
Zimbra 2013 has XSS in aspell.php