Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 03 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:-:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5800:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5801:*:*:*:*:*:* |
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. | |
| Title | Stored XSS Vulnerability | |
| First Time appeared |
Zohocorp
Zohocorp manageengine Exchange Reporter Plus |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zohocorp
Zohocorp manageengine Exchange Reporter Plus |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2026-04-04T03:55:29.128Z
Reserved: 2026-03-10T13:16:19.257Z
Link: CVE-2026-3880
Updated: 2026-04-03T12:47:38.909Z
Status : Analyzed
Published: 2026-04-03T12:16:18.933
Modified: 2026-04-03T18:27:41.177
Link: CVE-2026-3880
No data.
OpenCVE Enrichment
Updated: 2026-04-07T07:55:06Z