Zohocorp
Zohocorp Manageengine Exchange Reporter Plus: vulnerabilidades y CVE
Zohocorp Manageengine Exchange Reporter Plus tiene 28 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses15
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-27655 | Media (4.8) | 1.0% | — | 3 abr 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report. |
| CVE-2026-4108 | Media (4.8) | 1.0% | — | 3 abr 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. |
| CVE-2026-4107 | Media (5.4) | 1.0% | — | 3 abr 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. |
| CVE-2026-3880 | Media (4.8) | 1.0% | — | 3 abr 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. |
| CVE-2026-3879 | Media (4.8) | 1.0% | — | 3 abr 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. |
| CVE-2026-28703 | Media (4.8) | 1.0% | — | 3 abr 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report. |
| CVE-2026-28756 | Media (4.8) | 1.0% | — | 3 abr 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. |
| CVE-2026-28754 | Media (4.8) | 1.0% | — | 3 abr 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report. |
| CVE-2025-7633 | Media (6.1) | 0.49% | — | 11 nov 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report. |
| CVE-2025-7632 | Media (5.4) | 0.49% | — | 11 nov 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report. |
| CVE-2025-7430 | Media (5.4) | 0.49% | — | 11 nov 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report. |
| CVE-2025-7429 | Media (5.4) | 0.49% | — | 11 nov 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report. |
| CVE-2025-5347 | Media (5.4) | 0.45% | — | 30 oct 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module. |
| CVE-2025-5343 | Media (5.4) | 0.45% | — | 30 oct 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option. |
| CVE-2025-5342 | Media (6.5) | 1.1% | — | 30 oct 2025 | Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module. |
| CVE-2025-5966 | Alta (8.1) | 1.3% | — | 26 jun 2025 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. |
| CVE-2025-5366 | Alta (8.1) | 1.3% | — | 26 jun 2025 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report. |
| CVE-2025-3835 | Crítica (9.6) | 2.2% | — | 9 jun 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. |
| CVE-2024-9459 | Alta (8.8) | 4.5% | — | 5 nov 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module. |
| CVE-2024-6204 | Alta (8.1) | 2.0% | — | 30 ago 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module. |
| CVE-2024-38872 | Alta (8.8) | 3.1% | — | 26 jul 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module. |
| CVE-2024-38871 | Alta (8.8) | 3.1% | — | 26 jul 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module. |
| CVE-2024-21775 | Alta (8.8) | 5.0% | — | 16 feb 2024 | Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature. |
| CVE-2023-6105 | Media (5.5) | 0.69% | — | 15 nov 2023 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product… |
| CVE-2023-35785 | Alta (8.1) | 2.4% | — | 28 ago 2023 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data… |
| CVE-2023-22624 | Alta (7.5) | 3.2% | — | 17 ene 2023 | Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks. |
| CVE-2022-29457 | Alta (8.8) | 7.9% | — | 18 abr 2022 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. |
| CVE-2020-24786 | Crítica (9.8) | 13% | — | 31 ago 2020 | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Zohocorp
Manageengine Opmanager · 63Manageengine Applications Manager · 59Manageengine Adselfservice Plus · 56Manageengine Adaudit Plus · 53Manageengine Admanager Plus · 53Manageengine Servicedesk Plus · 50Manageengine Desktop Central · 48Manageengine Supportcenter Plus · 31Manageengine Netflow Analyzer · 30Manageengine Servicedesk Plus MSP · 26Manageengine Assetexplorer · 26Manageengine Password Manager PRO · 25