Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 03 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:-:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5800:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5801:*:*:*:*:*:* |
Fri, 03 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. | |
| Title | Stored XSS Vulnerability | |
| First Time appeared |
Zohocorp
Zohocorp manageengine Exchange Reporter Plus |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zohocorp
Zohocorp manageengine Exchange Reporter Plus |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2026-04-04T03:55:24.331Z
Reserved: 2026-03-13T11:43:54.683Z
Link: CVE-2026-28756
Updated: 2026-04-03T12:08:17.860Z
Status : Analyzed
Published: 2026-04-03T11:17:05.767
Modified: 2026-04-03T18:52:01.003
Link: CVE-2026-28756
No data.
OpenCVE Enrichment
Updated: 2026-04-07T07:55:09Z