{"id":"CVE-2025-66376","details":"Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.","modified":"2026-04-10T05:34:18.991929Z","published":"2026-01-05T15:15:44.903Z","references":[{"type":"WEB","url":"https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66376"},{"type":"ADVISORY","url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.18#Security_Fixes"},{"type":"ADVISORY","url":"https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.13#Security_Fixes"},{"type":"ADVISORY","url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories"},{"type":"ADVISORY","url":"https://wiki.zimbra.com/wiki/Security_Center"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zimbra/zm-build","events":[{"introduced":"b68c7b31a1d94f94903a79c53f1bd316b792de1d"},{"fixed":"c2fac09a3333bcb767866afa3203541da2e8729c"},{"introduced":"52b539ef205db233bfd8116e8130e27735b4153c"},{"fixed":"1884e94c76d9602c75dff36c9ff9a5ec2224c582"}],"database_specific":{"versions":[{"introduced":"10.0.0"},{"fixed":"10.0.18"},{"introduced":"10.1.0"},{"fixed":"10.1.13"}]}}],"versions":["10.0.0-GA","10.0.1","10.0.13","10.0.16","10.0.4","10.0.5","10.0.6","10.0.9","10.1.0","10.1.1","10.1.10","10.1.4","10.1.5","10.1.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66376.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}