Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Zohocorp — Vulnerabilities & Security Advisories 46

Browse all 46 CVE security advisories affecting Zohocorp. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Zohocorp primarily develops and distributes web application servers, most notably the Zimbra Collaboration Suite, which facilitates enterprise email and document management. Security audits have identified thirty-five Common Vulnerabilities and Exposures (CVEs) associated with its software ecosystem. Historically, these flaws predominantly involve remote code execution and cross-site scripting, allowing attackers to bypass authentication or inject malicious scripts into web interfaces. Privilege escalation vulnerabilities have also been documented, enabling unauthorized users to gain administrative control over compromised systems. While no single catastrophic incident defines the company’s entire history, the recurring nature of these critical flaws highlights persistent challenges in input validation and access control within its legacy codebase. The accumulation of these CVEs underscores the necessity for rigorous patch management and continuous security monitoring for organizations relying on Zohocorp’s infrastructure, as unaddressed vulnerabilities remain a significant risk vector for data breaches and system compromise.

CVE ID Title CVSS Severity Published
CVE-2026-14828 ZOHO ManageEngine Password Manager Pro SQL注入漏洞 — ManageEngine Password Manager Pro CWE-89 8.8 High 2026-09-02
CVE-2026-12263 Authentication Bypass — ManageEngine Password Manager Pro CWE-347 8.8 High 2026-08-13
CVE-2026-11840 SQL Injection — ManageEngine Password Manager Pro CWE-89 8.8 High 2026-08-13
CVE-2026-12571 Authentication Bypass Leading to Account Takeover — manageengine_ddi_central CWE-287 9.8 Critical 2026-08-11
CVE-2026-16053 Path Traversal — ManageEngine M365 Manager Plus CWE-23 8.5 High 2026-08-11
CVE-2026-6516 Remote Code Execution — ManageEngine ADAudit Plus CWE-78 10.0 Critical 2026-07-23
CVE-2026-3183 Multi Factor Auth Bypass — ManageEngine ADSelfService Plus CWE-290 7.1 High 2026-07-21
CVE-2026-3182 Sensitive Data Exposure — ManageEngine Endpoint Central CWE-319 4.3 Medium 2026-07-21
CVE-2026-11374 Account Takeover via Predictable SSO Ticket Generation — manageengine_adselfservice_plus CWE-340 9.0 Critical 2026-06-23
CVE-2026-8174 Cross-site Request Forgery — Zoho Mail wordpress plugin CWE-352 5.7 Medium 2026-05-26
CVE-2026-2740 Remote Code Execution — ManageEngine ADSelfService Plus CWE-77 8.4 High 2026-05-21
CVE-2026-3324 Authentication Bypass — ManageEngine Log360 CWE-288 8.2 High 2026-04-16
CVE-2026-5785 SQL Injection — ManageEngine PAM360 CWE-89 8.1 High 2026-04-16
CVE-2026-27655 Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 7.3 High 2026-04-03
CVE-2026-4108 Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 7.3 High 2026-04-03
CVE-2026-4107 Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 7.3 High 2026-04-03
CVE-2026-3880 Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 7.3 High 2026-04-03
CVE-2026-3879 Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 7.3 High 2026-04-03
CVE-2026-28703 Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 7.3 High 2026-04-03
CVE-2026-28756 Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 7.3 High 2026-04-03
CVE-2026-28754 Stored XSS Vulnerability — ManageEngine Exchange Reporter Plus CWE-79 7.3 High 2026-04-03
CVE-2026-1367 SQL Injection — ManageEngine ADSelfService Plus CWE-89 8.3 High 2026-02-23
CVE-2025-9226 Stored XSS — ManageEngine OpManager CWE-79 4.6 Medium 2026-01-30
CVE-2025-11669 Broken Access Control — ManageEngine PAM360 CWE-862 8.1 High 2026-01-13
CVE-2025-11250 Authentication Bypass — ManageEngine ADSelfService Plus CWE-290 9.1 Critical 2026-01-13
CVE-2025-9435 Path Traversal — ManageEngine ADManager Plus CWE-22 5.5 Medium 2026-01-13
CVE-2025-9787 Stored XSS — ManageEngine Applications Manager CWE-79 6.1 Medium 2025-12-18
CVE-2025-11670 NTLM Hash Exposure Vulnerability — ManageEngine ADManager Plus CWE-200 6.4 Medium 2025-12-15
CVE-2025-9227 Stored XSS — ManageEngine OpManager CWE-79 6.5 Medium 2025-11-11
CVE-2025-9223 Command Injection — ManageEngine Applications Manager CWE-77 8.8 High 2025-11-11

This page lists every published CVE security advisory associated with Zohocorp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.