CVE-2025-32354HIGH 8.8EPSS p18.2%

CVE-2025-32354CVE-2025-32354

Description

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform unauthorized GraphQL operations, such as modifying contacts, changing account settings, and accessing sensitive user data when an authenticated user visits a malicious website.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS0.27% probability of exploitation · percentile 18.2% · 2026-06-18T12:00:27Z
Published2025-04-29
Last modified2025-06-11

Underlying weaknesses· 1

CWE-352

References

  1. https://wiki.zimbra.com/wiki/Security_Center
  2. https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.4#Security_Fixes
  3. https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy

1

TypeTargetConfidenceTier
WeaknessCross-Site Request Forgery (CSRF)cwe-3520%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-33373
CVE
CVE-2025-25064
CVE
CVE-2025-54391
CVE
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
CVE
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.