216.73.217.22

CVE-2025-66376

· Published 05/01/2026 16:15 · Modified 19/03/2026 15:17 · Author: The MITRE Corporation

Labels: CVE-2025-66376 2026-01-05CVE-2025-66376CWE-79[email protected]

Essential information

Published
05/01/2026 16:15
Modified
19/03/2026 15:17
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
7.2 HIGH (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:L/I:L/A:N

CVSS metrics

Description

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
zimbra / zimbra collaboration cpe:2.3:a:zimbra:zimbra_collaboration:<10.0.18:*:*:*:*:*:*:*
zimbra / zimbra collaboration cpe:2.3:a:zimbra:zimbra_collaboration:<10.1.13:*:*:*:*:*:*:*

References