CVE-2024-27443
CWE-79
80.6
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.
Source: NVD
Signals
- CVSS
- 6.1
- Medium · v3.1
- EPSS
- 23.63%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since May 2025
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-79
- Published
- 12 Aug 2024
- Last modified 31 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-27443Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time