CVE-2025-9428High· 8.3▾ TwilightZohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 5.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
27%
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
manageengine_analytics_plus < 6.1manageengine_analytics_plus = 6.1Upgrade past the affected range:
manageengine_analytics_plus 6.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86677High· 8.8ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
CVE-2026-14913High· 8.8ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
CVE-2026-18912High· 7.7ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0
CVE-2025-10405High· 7.3A vulnerability was determined in itsourcecode Baptism Information Management System 1.0
CVE-2025-10479High· 7.3A security flaw has been discovered in SourceCodester Online Student File Management System 1.0