Manageengine Analytics Plus

Vendor:

First CVE: Jun 18, 2019 · Active for 7 years

8
Total CVEs
More Total CVEs than 87% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 76% of tracked products
12.5%
KEV Rate
Higher KEV Rate than 99% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Manageengine Analytics Plus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2019
7 years ago
Most Recent CVE
Nov 11, 2025
259 days ago

CVE Severity & Scoring

Manageengine Analytics Plus8 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None4 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java
Jan 18, 20239.899YESYES
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
Oct 21, 20258.842NONO
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
Aug 15, 20229.834NONO
Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.
Nov 11, 20259.831NONO
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan
Aug 15, 20227.526NONO
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, t
Jun 18, 20197.824NONO
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to t
Nov 27, 20248.123NONO
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host
Nov 15, 20235.517NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
1 CVE
12.5% of CVEs· 99th percentile
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Manageengine Analytics Plus

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.118.825.7%00
5.119.899.8%11
4.319.87.9%00
4.219.87.9%00
4.119.87.9%00
4.019.87.9%00
3.919.87.9%00
3.819.87.9%00
3.719.87.9%00
3.619.87.9%00
3.519.87.9%00
3.419.87.9%00
3.319.87.9%00
3.219.87.9%00
3.119.87.9%00
3.019.87.9%00
2.919.87.9%00
1.017.81.8%00