CVE-2023-50808: Zimbra Collaboration

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.

Affected products

  • Zimbra Collaboration: before 9.0.0 (fixed in 9.0.0); version 9.0.0 only

Published 2024-02-13. Last modified 2026-06-17.