← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Netflow Analyzer
Jun 17, 2026
May 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
1Zohocorp
1Manageengine Firewall Analyzer
Jun 17, 2026
May 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.
1Zohocorp
1Manageengine Firewall Analyzer
Jun 17, 2026
May 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
1Zohocorp
1Manageengine Firewall Analyzer
Jun 17, 2026
May 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.
1Zohocorp
1Manageengine Admanager Plus
Nov 21, 2024
Apr 30, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Apr 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
1Zohocorp
1Servicedesk Plus
Jun 17, 2026
Apr 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the...Show more
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 23, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious...Show more
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 22, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For exam...Show more
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Apr 4, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an a...Show more
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Nov 21, 2024
Mar 25, 2019
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
1Zohocorp
1Manageengine Servicedesk Plus
Nov 21, 2024
Mar 25, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
1Zohocorp
1Manageengine Netflow Analyzer
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter.
1Zohocorp
1Manageengine Netflow Analyzer
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot,...Show more
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903.Show less
1Zohocorp
1Manageengine Netflow Analyzer
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.
1Zohocorp
1Manageengine Netflow Analyzer
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Feb 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Feb 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jan 3, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.