Zoho operates a portfolio of cloud-based business applications spanning customer relationship management, marketing automation, and remote-access infrastructure, with its vulnerability disclosures concentrated in web-facing and administrative interfaces. The recurring weakness classes—cross-site request forgery, cross-site scripting, SQL injection, and privilege-management issues—reflect the input-handling and access-control demands of large, multi-tenant SaaS platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zoho over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42956HIGH Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, th | Nov 17, 2021 | 8.8 | 26 | NO | NO |
CVE-2019-15645HIGH The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. | Aug 27, 2019 | 8.8 | 25 | NO | NO |
CVE-2024-37225HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Automation.This issue affects Zoho Marketing Automation: from n | Jul 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-32442HIGH Cross-Site Request Forgery (CSRF) vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.7. | Apr 15, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-32441HIGH Cross-Site Request Forgery (CSRF) vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.7. | Apr 15, 2024 | 8.8 | 23 | NO | NO |
CVE-2019-5963HIGH Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | Jul 5, 2019 | 8.8 | 23 | NO | NO |
CVE-2019-5962MEDIUM Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jul 5, 2019 | 6.1 | 22 | NO | NO |
CVE-2019-19306MEDIUM The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName. | Nov 26, 2019 | 5.4 | 19 | NO | NO |
CVE-2019-15644MEDIUM The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS. | Aug 27, 2019 | 6.1 | 19 | NO | NO |
CVE-2014-6686MEDIUM The Zoho Books - Accounting App (aka com.zoho.books) application 3.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to | Sep 23, 2014 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zoho.
Media articles that mention a CVE ID that affects a product developed by Zoho — matched by CVE ID, not by vendor name.