GHSA-wmq6-ffv7-gqwf · Severity: medium — An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross...
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction.
Conclusion & alert: CVE-2025-48700 is rated Critical Active Threat (85.9/100): CVSS Medium severity, with high exploitation likelihood (EPSS 18.19%, 95th percentile). Core evidence: CISA KEV confirms active exploitation (added 2026-04-20) affecting Synacor / Zimbra Collaboration Suite (ZCS). cross-site scripting (CWE-79) Unauthenticated remote administrative access may be possible. EPSS rose +3.18% over the last day, indicating growing attacker interest. Mandatory action: Assess exposure and apply mitigations immediately; prioritize emergency patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
KEV catalog lead: This CVE appears in the CISA Known Exploited Vulnerabilities catalog (in-the-wild exploitation signal). Full KEV detail: CVE-2025-48700 on KEV · Exploit-DB search ↗
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-23 | 15.01% | 18.19% | +3.18% |
| 2 | 2026-05-22 | 18.76% | 15.01% | -3.75% |
| 3 | 2026-04-25 | — | 18.76% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-wmq6-ffv7-gqwf · Severity: medium — An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| synacor | zimbra_collaboration_suite | >= 10.0.0, < 10.0.12 | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | >= 10.1.0, < 10.1.4 | cpe:2.3:a:synacor:zimbra_collaboration_suite:*:*:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:-:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p1:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p10:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p11:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p12:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p13:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p14:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p15:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p16:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p17:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p18:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p19:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p2:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p20:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p21:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p22:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p23:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p24:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p25:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p26:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p27:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p28:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p29:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p3:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p30:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p31:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p31.1:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p32:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p33:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p34:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p35:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p36:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p37:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p38:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p39:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p4:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p40:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p41:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p42:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p43:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p44:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p45:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p46:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p5:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p6:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p7:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p8:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 8.8.15 | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p9:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:-:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p1:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p10:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p11:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p12:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p13:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p14:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p15:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p16:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p17:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p18:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p19:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p2:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p20:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p21:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p22:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p23:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p24:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p24.1:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p25:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p26:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p27:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p28:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p29:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p3:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p30:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p31:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p32:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p33:*:*:*:*:*:* |
| synacor | zimbra_collaboration_suite | 9.0.0 | cpe:2.3:a:synacor:zimbra_collaboration_suite:9.0.0:p34:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://wiki.zimbra.com/wiki/Security_Center | Release Notes |
| https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy | Product |
| https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48700 | US Government Resource |