📦 Manageengine Exchange Reporter Plus

by Zohocorp

🔍 What is Manageengine Exchange Reporter Plus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-3835

CRITICAL CVSS 9.6 Jun 9, 2025

This vulnerability allows remote attackers to execute arbitrary code on ManageEngine Exchange Reporter Plus servers through the Content Search module. It affects all organizations running vulnerable v...

CVE-2025-7430

HIGH CVSS 7.3 Nov 11, 2025

This stored cross-site scripting (XSS) vulnerability in ManageEngine Exchange Reporter Plus allows attackers to inject malicious scripts into the Folder Message Count and Size report. When users view ...

CVE-2025-7632

HIGH CVSS 7.3 Nov 11, 2025

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below contain a stored cross-site scripting (XSS) vulnerability in the Public Folders report feature. This allows attackers to inject mal...

CVE-2025-7633

HIGH CVSS 7.3 Nov 11, 2025

This stored cross-site scripting (XSS) vulnerability in ManageEngine Exchange Reporter Plus allows attackers to inject malicious scripts into custom reports. When users view these reports, the scripts...

CVE-2025-7429

HIGH CVSS 7.3 Nov 11, 2025

ManageEngine Exchange Reporter Plus versions 5723 and below contain a stored cross-site scripting (XSS) vulnerability in the 'Mails Deleted or Moved' report. This allows attackers to inject malicious ...

CVE-2025-5966

HIGH CVSS 8.1 Jun 26, 2025

This vulnerability allows attackers to inject malicious scripts into the 'Attachments by filename keyword' report feature in ManageEngine Exchange Reporter Plus. When users view these reports, the scr...

CVE-2024-6204

HIGH CVSS 8.3 Aug 30, 2024

This SQL injection vulnerability in Zohocorp ManageEngine Exchange Reporter Plus allows attackers to execute arbitrary SQL commands through the reports module. Organizations using versions before 5715...

CVE-2024-38871

HIGH CVSS 8.3 Jul 26, 2024

This vulnerability allows authenticated attackers to execute arbitrary SQL commands in ManageEngine Exchange Reporter Plus. Attackers with valid credentials can potentially access, modify, or delete d...

CVE-2025-5342

MEDIUM CVSS 4.3 Oct 30, 2025

This CVE describes a ReDOS (Regular Expression Denial of Service) vulnerability in Zohocorp ManageEngine Exchange Reporter Plus. Attackers can cause denial of service by sending specially crafted sear...

CVE-2025-5343

MEDIUM CVSS 6.3 Oct 30, 2025

This stored cross-site scripting vulnerability in ManageEngine Exchange Reporter Plus allows attackers to inject malicious scripts into the Instant Search feature. When users view compromised search r...

CVE-2025-5347

MEDIUM CVSS 6.3 Oct 30, 2025

This stored cross-site scripting vulnerability in Zohocorp ManageEngine Exchange Reporter Plus allows attackers to inject malicious scripts into reports that execute when viewed by other users. It aff...