CVE-2024-10839: Zohocorp ManageEngine SharePoint Manager Plus

High severity, CVSS 8.1. EPSS: 2.4% chance of exploitation in the next 30 days.

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

Affected products

  • Zohocorp ManageEngine SharePoint Manager Plus: version 4.0 only; version 4.1 only; version 4.2 only; version 4.3 only; version 4.4 only; version 4.5 only

Published 2024-11-08. Last modified 2026-06-17.