PT-2026-1290 · Zimbra · Zimbra Collaboration

Published

2026-01-05

·

Updated

2026-03-19

·

CVE-2025-66376

CVSS v3.1

7.2

High

AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zimbra Collaboration (ZCS) versions prior to 10.0.18 Zimbra Collaboration (ZCS) versions prior to 10.1.13
Description The software contains a stored cross-site scripting (XSS) issue within the Classic UI. This occurs due to Cascading Style Sheets (CSS) @import directives in an HTML email message. The issue allows for malicious code execution when a user views a crafted email.
Recommendations Update to Zimbra Collaboration (ZCS) version 10.0.18 or later. Update to Zimbra Collaboration (ZCS) version 10.1.13 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-01010
CVE-2025-66376

Affected Products

Zimbra Collaboration