Known vulnerabilities in Zoho ManageEngine ServiceDesk Plus MSP

Software CPE: cpe:2.3:a:zohocorp:zoho_manageengine_servicedesk_plus_msp:*:*:*:*:*:*:*:*
Total vulnerabilities: 51
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Zoho ManageEngine ServiceDesk Plus MSP Zoho ManageEngine ServiceDesk Plus MSP is affected by 51 known vulnerabilities: 2 high, 14 medium, 35 low Critical High Medium Low

Vulnerabilities (51)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114229 - Incorrect Regular Expression
CVE-2025-8309
CWE-185 Medium
No
No
14940 19.08.2025 SB2025081958
SB2025081959
SB2025081960
#VU113365 - Improper Control of Filename for Include/Require Statement in PHP Program
CVE-2025-3444
CWE-98 Medium
No
No
14920 28.07.2025 SB2025072889
#VU107048 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-50053
CWE-79 Low
No
No
14910 07.04.2025 SB2025040723
#VU79446 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
14305 11.08.2023 SB2023081125
#VU79445 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
14305 11.08.2023 SB2023081125
#VU79444 - Cross-Site Request Forgery (CSRF)
CWE-352 Low
No
No
14305 11.08.2023 SB2023081125
#VU79443 - Improper Access Control
CWE-284 Low
No
No
14305 11.08.2023 SB2023081125
#VU79442 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
14305 11.08.2023 SB2023081125
#VU79441 - Improper Access Control
CWE-284 Low
No
No
14305 11.08.2023 SB2023081125
#VU79440 - Improper Access Control
CWE-284 Low
No
No
14305 11.08.2023 SB2023081125
#VU79439 - Permissions, Privileges, and Access Controls
CWE-264 Low
No
No
14305 11.08.2023 SB2023081125
#VU79438 - Cleartext Storage of Sensitive Information
CWE-312 Low
No
No
14305 11.08.2023 SB2023081125
#VU79434 - Improper Access Control
CWE-284 Low
No
No
14305 11.08.2023 SB2023081125
#VU79418 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
14305 11.08.2023 SB2023081125
#VU79417 - Improper Access Control
CWE-284 Low
No
No
14305 11.08.2023 SB2023081125
#VU79415 - Improper Access Control
CWE-284 Low
No
No
14305 11.08.2023 SB2023081125
#VU79414 - Improper Access Control
CWE-284 Medium
No
No
14305 11.08.2023 SB2023081125
#VU79412 - Information Exposure Through Log Files
CWE-532 Low
No
No
14305 11.08.2023 SB2023081125
#VU79399 - Improper Access Control
CWE-284 Low
No
No
14305 11.08.2023 SB2023081125
#VU79395 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
14305 11.08.2023 SB2023081125


Showing elements 1 - 20 out of 51