CVE-2026-4107

HIGH

ManageEngine Exchange Reporter Plus < 5802 - Stored Cross-Site Scripting in Folder Message Count and Size Report

Title source: llm
STIX 2.1

Description

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

Scores

CVSS v3 7.3
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (3)
Zohocorp/ManageEngine Exchange Reporter Plus < 5802
zohocorp/manageengine_exchange_reporter_plus 5.8 (3 CPE variants)
zohocorp/manageengine_exchange_reporter_plus < 5.8
Published Apr 03, 2026
Tracked Since Apr 03, 2026