CVEs (51)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Apr 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jan 3, 2019 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. |
1Zohocorp 1Manageengine Adselfservice Plus Nov 21, 2024 Jan 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. |
1Zohocorp 1Manageengine Adselfservice Plus Nov 21, 2024 Dec 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. |
1Zohocorp 1Manageengine Adselfservice Plus Nov 21, 2024 Dec 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. |
1Zohocorp 1Manageengine Adselfservice Plus May 6, 2026 Jan 7, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ADSelfService Plus before 5.2 Build 5202 allows remote attackers to inject arbitrary web script or HTML via the name parameter to GroupSubscription.do. |
1Zohocorp 1Manageengine Adselfservice Plus Apr 29, 2026 Aug 23, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2)...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Apr 29, 2026 Feb 17, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script o...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Apr 29, 2026 Feb 17, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Apr 29, 2026 Feb 17, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access...Show more |