All verified exploits

CVE-2025-66376 Classic UI Stored XSS via CSS @import

Deterministic high Zimbra CISA KEV Added cve-verified-cve-2025-66376

Detects Zimbra instances running versions 10.0.0–10.0.17 or 10.1.0–10.1.12 where the AntiSamy HTML sanitizer doesn't strip CSS @import directives from emails. Attackers can send crafted emails that execute JavaScript when opened in Classic UI, enabling session hijacking and credential theft.

Is your app exploitable through CVE-2025-66376?

Scan your domain free