Servicedesk Plus
ManageEngine · 11 CVEs
User privilege escalation vulnerability
Aug 20, 2025
Stored XSS
Mar 21, 2025
Stored XSS
Aug 23, 2024
Stored XSS Vulnerability
May 27, 2024
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; Sup…
Aug 28, 2017
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5…
Aug 28, 2017
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ti…
Feb 4, 2015
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inje…
Aug 12, 2012
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus (SDP) before 8012 allows…
Sep 20, 2011
The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher f…
Sep 20, 2011
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remo…
Jul 17, 2011
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows r…
Jul 17, 2011
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows rem…
Jul 17, 2011
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Win…
Mar 12, 2008
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-8309 | User privilege escalation vulnerability | HIGH | 0.27% | Aug 20, 2025 |
| CVE-2024-50053 | Stored XSS | MEDIUM | 1.12% | Mar 21, 2025 |
| CVE-2024-41150 | Stored XSS | MEDIUM | 1.27% | Aug 23, 2024 |
| CVE-2024-27314 | Stored XSS Vulnerability | LOW | 1.91% | May 27, 2024 |
| CVE-2014-5302 | Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4… | HIGH | 10.73% | Aug 28, 2017 |
| CVE-2014-5301 | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. | HIGH | 78.38% | Aug 28, 2017 |
| CVE-2015-1480 | ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData… | MEDIUM | 6.26% | Feb 4, 2015 |
| CVE-2012-2585 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML via an e… | MEDIUM | 1.35% | Aug 12, 2012 |
| CVE-2011-1510 | Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus (SDP) before 8012 allows remote attackers to inject arbitrary we… | MEDIUM | 1.09% | Sep 20, 2011 |
| CVE-2011-1509 | The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, w… | MEDIUM | 0.79% | Sep 20, 2011 |
| CVE-2011-2757 | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via… | MEDIUM | 39.37% | Jul 17, 2011 |
| CVE-2011-2756 | FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a spe… | MEDIUM | 1.98% | Jul 17, 2011 |
| CVE-2011-2755 | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files vi… | MEDIUM | 30.88% | Jul 17, 2011 |
| CVE-2008-1299 | Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers to inject a… | MEDIUM | 0.81% | Mar 12, 2008 |
Showing 1 to 11 of 11 CVEs