CVE-2025-7429
HIGHZohocorp ManageEngine Exchange Reporter Plus <5.723 - XSS
Title source: llmDescription
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.
Scores
CVSS v3
7.3
EPSS
0.0004
EPSS Percentile
10.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (25)
zohocorp/manageengine_exchange_reporter_plus
< 5.6
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
... and 10 more
Timeline
Published
Nov 11, 2025
Tracked Since
Feb 18, 2026