ManageEngine Vulnerabilities and Affected Products
Vulnerabilities associated with Exchange Reporter Plus.
Products
Clear product- ADAudit Plus35 vulnerabilities
- adaudit_plus25 vulnerabilities
- Applications Manager8 vulnerabilities
- Exchange Reporter Plus8 vulnerabilities
- ADSelfService Plus5 vulnerabilities
- OpManager5 vulnerabilities
- Endpoint Central4 vulnerabilities
- ServiceDesk Plus MSP4 vulnerabilities
- Desktop Central3 vulnerabilities
- exchange_reporter_plus3 vulnerabilities
- PAM3603 vulnerabilities
- ServiceDesk Plus3 vulnerabilities
- SupportCenter Plus3 vulnerabilities
- ADManager Plus2 vulnerabilities
- Analytics Plus2 vulnerabilities
- Asset Explorer2 vulnerabilities
- DDI Central2 vulnerabilities
- servicedesk2 vulnerabilities
- Access Manager Plus1 vulnerability
- desktop_central1 vulnerability
- OpManager, OpManager Plus, OpManager MSP, OpManager Enterprise Edition1 vulnerability
- OpManager, Remote Monitoring and Management1 vulnerability
- Password Manager Pro1 vulnerability
- password_manager_pro1 vulnerability
- Service Desk Plus1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-5966HIGH | Stored XSSZohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. CWE-79Jun 26, 2025 | CVSS8.1v3.1 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5366HIGH | Stored XSSZohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report. CWE-79Jun 26, 2025 | CVSS8.1v3.1 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3835CRITICAL | Remote Code ExecutionZohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. CWE-434Jun 9, 2025 | CVSS9.6v3.1 | EPSS1.99% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9459HIGH | SQL InjectionZohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module. CWE-89Nov 5, 2024 | CVSS8.3v3.1 | EPSS2.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6204HIGH | SQL injectionZohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module. CWE-89Aug 30, 2024 | CVSS8.3v3.1 | EPSS1.96% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38872HIGH | SQL InjectionZohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module. CWE-89Jul 26, 2024 | CVSS8.3v3.1 | EPSS3.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38871HIGH | SQL InjectionZohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module. CWE-89Jul 26, 2024 | CVSS8.3v3.1 | EPSS3.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21775HIGH | SQL InjectionZoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature. CWE-89Feb 16, 2024 | CVSS8.3v3.1 | EPSS5.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |