
CVE-2026-3880 Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. https://www.cve.org/CVERecord?id=CVE-2026-3880
Post summary
CVE‑2026‑3880 exposes a stored XSS flaw in ManageEngine Exchange Reporter Plus (pre‑5802), enabling attacker‑inserted script via the Public Folder Client Permissions report.

