Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2025-66376

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
Back to all
CVE

CVE-2025-66376

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.2
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
C
H
U
-

Related Resources

No items found.

References

https://wiki.zimbra.com/wiki/SecurityCenter, https://wiki.zimbra.com/wiki/ZimbraReleases/10.0.18#SecurityFixes, https://wiki.zimbra.com/wiki/ZimbraReleases/10.1.13#SecurityFixes, https://wiki.zimbra.com/wiki/ZimbraResponsibleDisclosurePolicy, https://wiki.zimbra.com/wiki/ZimbraSecurityAdvisories, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66376, https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66376.json, https://nvd.nist.gov/vuln/detail/CVE-2025-66376

Severity

7.2

CVSS Score
0
10

Basic Information

Base CVSS
7.2
EPSS Probability
0.21973%
EPSS Percentile
0.97471%
Introduced Version
52b539ef205db233bfd8116e8130e27735b4153c,de2f187263204c5edbcd64ab4aad155367f27eef,5a574c4741e2713147c61524e30057679ece2ec6,0da199c818c28750b27aec8c2aa1fa8420086d4e
Fix Available
1884e94c76d9602c75dff36c9ff9a5ec2224c582,2aecfa967aa09146bbab421bd09c242a420fff0e,035c4371687d035685fd572d03a55e6cabf2383c,42bcab6250f9084ac05d771550755f9401403f65

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading