← Back to browse · API

CVE-2025-66376

Severity
HIGH
CVSS
7.2
EPSS
0.21973
Risk score
61.49
CISA KEV
Yes
PoC
No
Published
2026-01-05
Modified
2026-03-19
First seen
2026-08-07
Aliases
EUVD-2026-0850, GHSA-H7WG-85FJ-3C6G
Products
Synacor:Zimbra Collaboration Suite (ZCS), Zimbra:Collaboration 10.0 <10.0.18, Zimbra:Collaboration 10.1 <10.1.13
Sources
cisa.gov CVE-2025-66376
euvd EUVD-2026-0850

Description

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

References