« Back to list

CVE-2026-28754

Status: AnalyzedMedium (4.8)—

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-28754",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-28754",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-03T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.7
      }
    ]
  },
  "affected": [
    {
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "affectedData": [
        {
          "vendor": "Zohocorp",
          "product": "ManageEngine Exchange Reporter Plus",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5802",
              "versionType": "5802"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-03T11:17:05.543",
  "references": [
    {
      "url": "https://www.manageengine.com/products/exchange-reports/advisory/CVE-2026-28754.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report."
    },
    {
      "lang": "es",
      "value": "Las versiones de Zohocorp ManageEngine Exchange Reporter Plus anteriores a la 5802 son vulnerables a XSS almacenado en el informe de Listas de distribución."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A7FD58A-DC4B-4FBB-B20D-5050A0D321F1",
              "versionEndExcluding": "5.8"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94D09BE3-96E1-432B-9882-D7DF3C070CE2"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5800:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CCAB839F-E577-4CBB-9E43-DBC0BECFA8B1"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5801:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53414E87-0848-4245-9D58-9A74E550E3CC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "0fc0942c-577d-436f-ae8e-945763c79b02"
}