Browse all 46 CVE security advisories affecting Zohocorp. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Zohocorp primarily develops and distributes web application servers, most notably the Zimbra Collaboration Suite, which facilitates enterprise email and document management. Security audits have identified thirty-five Common Vulnerabilities and Exposures (CVEs) associated with its software ecosystem. Historically, these flaws predominantly involve remote code execution and cross-site scripting, allowing attackers to bypass authentication or inject malicious scripts into web interfaces. Privilege escalation vulnerabilities have also been documented, enabling unauthorized users to gain administrative control over compromised systems. While no single catastrophic incident defines the company’s entire history, the recurring nature of these critical flaws highlights persistent challenges in input validation and access control within its legacy codebase. The accumulation of these CVEs underscores the necessity for rigorous patch management and continuous security monitoring for organizations relying on Zohocorp’s infrastructure, as unaddressed vulnerabilities remain a significant risk vector for data breaches and system compromise.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-14828 | ZOHO ManageEngine Password Manager Pro SQL注入漏洞 — ManageEngine Password Manager Pro CWE-89 | 8.8 | High | 2026-09-02 |
| CVE-2026-12263 | Authentication Bypass — ManageEngine Password Manager Pro CWE-347 | 8.8 | High | 2026-08-13 |
| CVE-2026-11840 | SQL Injection — ManageEngine Password Manager Pro CWE-89 | 8.8 | High | 2026-08-13 |
| CVE-2026-12571 | Authentication Bypass Leading to Account Takeover — manageengine_ddi_central CWE-287 | 9.8 | Critical | 2026-08-11 |
| CVE-2026-16053 | Path Traversal — ManageEngine M365 Manager Plus CWE-23 | 8.5 | High | 2026-08-11 |
| CVE-2026-6516 | Remote Code Execution — ManageEngine ADAudit Plus CWE-78 | 10.0 | Critical | 2026-07-23 |
| CVE-2026-3183 | Multi Factor Auth Bypass — ManageEngine ADSelfService Plus CWE-290 | 7.1 | High | 2026-07-21 |
| CVE-2026-3182 | Sensitive Data Exposure — ManageEngine Endpoint Central CWE-319 | 4.3 | Medium | 2026-07-21 |
| CVE-2026-11374 | Account Takeover via Predictable SSO Ticket Generation — manageengine_adselfservice_plus CWE-340 | 9.0 | Critical | 2026-06-23 |
| CVE-2026-8174 | Cross-site Request Forgery — Zoho Mail wordpress plugin CWE-352 | 5.7 | Medium | 2026-05-26 |
| CVE-2026-2740 | Remote Code Execution — ManageEngine ADSelfService Plus CWE-77 | 8.4 | High | 2026-05-21 |
| CVE-2026-3324 | Authentication Bypass — ManageEngine Log360 CWE-288 | 8.2 | High | 2026-04-16 |
| CVE-2026-5785 | SQL Injection — ManageEngine PAM360 CWE-89 | 8.1 | High | 2026-04-16 |
| CVE-2026-27655 | Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 | 7.3 | High | 2026-04-03 |
| CVE-2026-4108 | Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 | 7.3 | High | 2026-04-03 |
| CVE-2026-4107 | Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 | 7.3 | High | 2026-04-03 |
| CVE-2026-3880 | Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 | 7.3 | High | 2026-04-03 |
| CVE-2026-3879 | Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 | 7.3 | High | 2026-04-03 |
| CVE-2026-28703 | Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 | 7.3 | High | 2026-04-03 |
| CVE-2026-28756 | Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 | 7.3 | High | 2026-04-03 |
| CVE-2026-28754 | Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 | 7.3 | High | 2026-04-03 |
| CVE-2026-1367 | SQL Injection — ManageEngine ADSelfService Plus CWE-89 | 8.3 | High | 2026-02-23 |
| CVE-2025-9226 | Stored XSS — ManageEngine OpManager CWE-79 | 4.6 | Medium | 2026-01-30 |
| CVE-2025-11669 | Broken Access Control — ManageEngine PAM360 CWE-862 | 8.1 | High | 2026-01-13 |
| CVE-2025-11250 | Authentication Bypass — ManageEngine ADSelfService Plus CWE-290 | 9.1 | Critical | 2026-01-13 |
| CVE-2025-9435 | Path Traversal — ManageEngine ADManager Plus CWE-22 | 5.5 | Medium | 2026-01-13 |
| CVE-2025-9787 | Stored XSS — ManageEngine Applications Manager CWE-79 | 6.1 | Medium | 2025-12-18 |
| CVE-2025-11670 | NTLM Hash Exposure Vulnerability — ManageEngine ADManager Plus CWE-200 | 6.4 | Medium | 2025-12-15 |
| CVE-2025-9227 | Stored XSS — ManageEngine OpManager CWE-79 | 6.5 | Medium | 2025-11-11 |
| CVE-2025-9223 | Command Injection — ManageEngine Applications Manager CWE-77 | 8.8 | High | 2025-11-11 |
This page lists every published CVE security advisory associated with Zohocorp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.