Vulnerabilities & Exploits · Web App Attack

Classic Web Client XSS Puts Mail Sessions at Risk

The weak point is the authenticated mail session, not the gateway. In Zimbra’s Classic Web Client, opening a specially crafted message can run attacker-controlled code inside the user’s browser session, which puts mailbox content, session data, and account settings within reach.

Zimbra says version 10.1.19 fixes the issue, and the flaw is tracked as CVE-2025-27915. The concern is that standard email filtering does not remove the risk once the message lands, because the trigger is the user opening it in the web client.

For teams still running the Classic Web Client, the practical question is exposure to a mail-view XSS that works inside trusted sessions. That makes patch status the key control, especially in higher-sensitivity environments where mailbox access is the real target.

3 sources · Jul 13

CVE-2025-66376

NVD KEV

Known exploited · CISA KEV

CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 12% (96th percentile).

CISA federal remediation date Apr 1 · date passed

CVE-2025-48700

NVD KEV

Known exploited · CISA KEV

CVSS 6.1 MEDIUM: an issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. EPSS 2% (75th percentile).

CISA federal remediation date Apr 23 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-07-11

Every edition of this story: Classic Web Client XSS Puts Mail Sessions at Risk

More from today