CVE-2025-27914: Zimbra Collaboration

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth token and involves a crafted URL with manipulated query parameters that triggers XSS when accessed by a victim.

Affected products

  • Zimbra Collaboration: from 10.0.0, before 10.0.11 (fixed in 10.0.11); version 9.0.0 only; version 10.1.0 only

Published 2025-03-12. Last modified 2026-06-17.