VendorsZoho Corpmanageengine_admanager_plusall versions
Vulnerabilities

Zoho Corp ManageEngine ADManager Plus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2025-11670
NTLM Hash Exposure Vulnerability
Published 2025-12-15 · Analyzed
6.4EPSS 0.004
CVE-2018-15740
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
Published 2018-08-28 · Modified
6.11 PoCEPSS 0.061
CVE-2020-35594
Zoho ManageEngine ADManager Plus before 7066 allows XSS.
Published 2021-03-05 · Modified
6.1EPSS 0.010
CVE-2021-36771
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
Published 2021-07-17 · Modified
6.1EPSS 0.009
CVE-2021-36772
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
Published 2021-07-17 · Modified
6.1EPSS 0.009
CVE-2023-6105
ManageEngine Information Disclosure in Multiple Products
Published 2023-11-15 · Modified
5.5EPSS 0.007
CVE-2025-9435
Path Traversal
Published 2026-01-13 · Analyzed
5.5EPSS 0.006
CVE-2023-41904
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
Published 2023-09-26 · Modified
5.4EPSS 0.020
CVE-2021-37922
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.
Published 2021-10-07 · Modified
5.3EPSS 0.023
CVE-2023-39912
Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.
Published 2023-08-31 · Analyzed
4.9EPSS 0.038
CVE-2023-35786
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
Published 2023-07-05 · Modified
4.9EPSS 0.030
CVE-2015-1026
Multiple cross-site scripting (XSS) vulnerabilities in ZOHO ManageEngine ADManager Plus before 6.2 Build 6270 allow remote attackers to inject arbitrary web script or HTML via the (1) technicianSearchText parameter to the Help Desk Technician page or (2) rolesSearchText parameter to the Help Desk Roles.
Published 2015-03-11 · Modified
4.3EPSS 0.036
CVE-2010-5050
Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2011-11-23 · Modified
4.3EPSS 0.032
← Prev2 / 2