Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
synacor zimbra collaboration suite vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2016-9924
Zimbra Collaboration Suite (ZCS) prior to 8.7.4 allows remote malicious users to conduct XML External Entity (XXE) attacks.
Synacor Zimbra Collaboration Suite
4.3
CVSSv2
CVE-2017-17703
Synacor Zimbra Collaboration Suite (ZCS) prior to 8.8.3 has Persistent XSS.
Synacor Zimbra Collaboration Suite
6.8
CVSSv2
CVE-2016-3403
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration prior to 8.6.0 Patch 8 allow remote malicious users to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging f...
Synacor Zimbra Collaboration Suite
4.3
CVSSv2
CVE-2016-3407
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration prior to 8.7.0 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104222, 104910, 105071, and 105175.
Synacor Zimbra Collaboration Suite
4.3
CVSSv2
CVE-2016-3412
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration prior to 8.7.0 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103997, 104413, 104414, 104777, and 104791.
Synacor Zimbra Collaboration Suite
3.5
CVSSv2
CVE-2017-8783
Synacor Zimbra Collaboration Suite (ZCS) prior to 8.7.10 has Persistent XSS.
Synacor Zimbra Collaboration Suite
4.3
CVSSv2
CVE-2015-7609
Synacor Zimbra Mail Client 8.6 prior to 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.
Synacor Zimbra Collaboration Suite 8.6.0
4.3
CVSSv2
CVE-2020-18984
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated malicious users to execute arbitrary web scripts or HTML via a host header injection.
Synacor Zimbra Collaboration Suite 8.8.12
5.8
CVSSv2
CVE-2020-18985
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows malicious users to redirect users to any arbitrary website of their choosing.
Synacor Zimbra Collaboration Suite 8.8.12
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
man-in-the-middle
command injection
CVE-2021-47511
CVE-2024-26238
CVE-2024-4858
CVE-2024-21305
XXE
CVE-2021-47555
CVE-2021-47526
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5