VYPR

Vendor CVEs

Zoho

All CVEs

422 total · sorted by risk
  • CVE-2019-12541MedJun 5, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.

  • CVE-2019-12538MedJun 5, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.

  • CVE-2019-12189MedMay 21, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.

  • CVE-2019-8928MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.

  • CVE-2019-8927MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup,…

  • CVE-2019-8926MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.

  • CVE-2018-20485MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

  • CVE-2018-20484MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

  • CVE-2018-15740MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.06

    Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.

  • CVE-2018-15608MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.02

    Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

  • CVE-2025-57963MedSep 22, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing zoho-subscriptions allows DOM-Based XSS.This issue affects Zoho Billing: from n/a through <= 4.1.

  • CVE-2025-46453MedApr 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreatorTeam Zoho Creator Forms allows Stored XSS. This issue affects Zoho Creator Forms: from n/a through 1.0.5.

  • CVE-2025-30900MedMar 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing – Embed Payment Form allows Stored XSS. This issue affects Zoho Billing – Embed Payment Form: from n/a through 4.0.

  • CVE-2024-47633MedOct 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Zoho Forms zoho-forms allows Stored XSS.This issue affects Zoho Forms: from n/a through <= 4.0.

  • CVE-2024-38752MedAug 13, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campaigns allows Cross-Site Scripting (XSS).This issue affects Zoho Campaigns: from n/a through 2.0.8.

  • CVE-2023-38332MedAug 4, 2023
    risk 0.42cvss 6.5epss 0.04

    Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.

  • CVE-2022-40772MedNov 23, 2022
    risk 0.42cvss 6.5epss 0.03

    Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.

  • CVE-2022-24447MedMar 2, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

  • CVE-2022-23863MedJan 28, 2022
    risk 0.42cvss 6.5epss 0.02

    Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.

  • CVE-2021-46166MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.03

    Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.

  • CVE-2021-35512MedOct 21, 2021
    risk 0.42cvss 6.5epss 0.02

    An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

  • CVE-2021-37420MedSep 21, 2021
    risk 0.42cvss 6.5epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

  • CVE-2020-13154MedMay 18, 2020
    risk 0.42cvss 6.5epss 0.03

    Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.

  • CVE-2020-8838MedMar 23, 2020
    risk 0.42cvss 6.4epss 0.02

    An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines…

  • CVE-2017-11561MedMay 23, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.

  • CVE-2024-36038MedJun 24, 2024
    risk 0.41cvss 6.3epss 0.01

    Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.

  • CVE-2024-27313MedMay 29, 2024
    risk 0.41cvss 6.3epss 0.01

    Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.

  • CVE-2021-31813MedJul 1, 2021
    risk 0.41cvss 5.4epss 0.78

    Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.

  • CVE-2020-27449MedAug 11, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.

  • CVE-2023-38333MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.

  • CVE-2023-29442MedApr 26, 2023
    risk 0.40cvss 6.1epss 0.09

    Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.

  • CVE-2023-23078MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.

  • CVE-2023-23077MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.

  • CVE-2023-23075MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.

  • CVE-2023-23073MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.

  • CVE-2022-24681MedApr 7, 2022
    risk 0.40cvss 6.1epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

  • CVE-2021-43295MedNov 30, 2021
    risk 0.40cvss 6.1epss 0.03

    Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.

  • CVE-2021-43294MedNov 30, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.

  • CVE-2021-37416MedAug 30, 2021
    risk 0.40cvss 6.1epss 0.03

    Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

  • CVE-2021-40178MedAug 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.

  • CVE-2021-40176MedAug 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine Log360 before Build 5225 allows stored XSS.

  • CVE-2021-36772MedJul 17, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.

  • CVE-2021-36771MedJul 17, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.

  • CVE-2021-27956MedMay 20, 2021
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.

  • CVE-2020-35594MedMar 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine ADManager Plus before 7066 allows XSS.

  • CVE-2021-27214MedFeb 19, 2021
    risk 0.40cvss 6.1epss 0.02

    A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative…

  • CVE-2020-15521MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .

  • CVE-2019-15510MedMar 23, 2020
    risk 0.40cvss 6.1epss 0.03

    ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.

  • CVE-2019-18781MedDec 18, 2019
    risk 0.40cvss 6.1epss 0.02

    An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.

  • CVE-2019-15644MedAug 27, 2019
    risk 0.40cvss 6.1epss 0.01

    The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.

Page 6 of 9