Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.
| Vendor | Product | Versions |
|---|---|---|
| zoho | manageengine exchange reporter plus | 0, 5801 |
Updated affected versions to include 5801, confirmed no exploit available, and added CVE ID CVE-2026-28756.
Initial creation