CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

zohocorp

manageengine_exchange_reporter_plus

28 known vulnerabilities · sorted by CVSS score

CVE-2020-24786
CRITICAL9.8

An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.

zohocorp / manageengine_adselfservice_plus+151
Network
Published Aug 31, 2020
Page 1 of 2
CVE-2025-3835
CRITICAL9.6

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

zohocorp / manageengine_exchange_reporter_plus+22
Network
Published Jun 9, 2025
CVE-2022-29457
HIGH8.8

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

zohocorp / manageengine_adaudit_plus+63
Network
Published Apr 18, 2022
CVE-2024-21775
HIGH8.3

Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.

zohocorp / manageengine_exchange_reporter_plus+16
Network
Published Feb 16, 2024
CVE-2024-6204
HIGH8.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

zohocorp / manageengine_exchange_reporter_plus+16
Network
Published Aug 30, 2024
CVE-2024-38871
HIGH8.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

zohocorp / manageengine_exchange_reporter_plus+17
Network
Published Jul 26, 2024
CVE-2024-38872
HIGH8.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.

zohocorp / manageengine_exchange_reporter_plus+17
Network
Published Jul 26, 2024
CVE-2024-9459
HIGH8.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.

zohocorp / manageengine_exchange_reporter_plus+19
Network
Published Nov 5, 2024
CVE-2025-5366
HIGH8.1

Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.

zohocorp / manageengine_exchange_reporter_plus+23
Network
Published Jun 26, 2025
CVE-2023-35785
HIGH8.1

Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360 UEBA 4045 and below, M365 Manager Plus 4529 and below, M365 Security Plus 4529 and below, Recovery Manager Plus 6061 and below, ServiceDesk Plus 14204 and below and 143xx 14302 and below, ServiceDesk Plus MSP 14300 and below, SharePoint Manager Plus 4402 and below, and Support Center Plus 14300 and below are vulnerable to 2FA bypass via a few TOTP authenticators. Note: A valid pair of username and password is required to leverage this vulnerability.

zohocorp / manageengine_ad360+234
Network
Published Aug 28, 2023
CVE-2025-5966
HIGH8.1

Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.

zohocorp / manageengine_exchange_reporter_plus+23
Network
Published Jun 26, 2025
CVE-2023-22624
HIGH7.5

Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.

zohocorp / manageengine_exchange_reporter_plus+8
Network
Published Jan 17, 2023
CVE-2026-28703
HIGH7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.

zohocorp / manageengine_exchange_reporter_plus+3
Network
Published Apr 3, 2026
CVE-2025-7633
HIGH7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.

zohocorp / manageengine_exchange_reporter_plus+24
Network
Published Nov 11, 2025
CVE-2026-27655
HIGH7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.

zohocorp / manageengine_exchange_reporter_plus+3
Network
Published Apr 3, 2026
CVE-2025-7429
HIGH7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.

zohocorp / manageengine_exchange_reporter_plus+24
Network
Published Nov 11, 2025
CVE-2025-7430
HIGH7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.

zohocorp / manageengine_exchange_reporter_plus+24
Network
Published Nov 11, 2025
CVE-2025-7632
HIGH7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.

zohocorp / manageengine_exchange_reporter_plus+24
Network
Published Nov 11, 2025
CVE-2026-3879
HIGH7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.

zohocorp / manageengine_exchange_reporter_plus+3
Network
Published Apr 3, 2026
CVE-2026-3880
HIGH7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.

zohocorp / manageengine_exchange_reporter_plus+3
Network
Published Apr 3, 2026