EasyCloudify™
Products
  • Cloud PlatformImprove team productivity and integrate popular workflow applications.
  • Cloud Servers (VPS)NVMe SSD servers deployed in under 60 seconds.
  • Object StorageS3-compatible storage with built-in global CDN.
  • Managed DatabasesManaged PostgreSQL, MySQL, MongoDB, Valkey, Kafka & OpenSearch.
  • Managed WordPressManaged WordPress hosting, so you can focus on your business.
  • MarketplaceFind an app that suits you, then spin it up in 60 seconds or less.
  • Mail HostingPrivacy First Email Hosting for your business.
  • SEO & AI Visibility AuditAudit your site for SEO and AI answer engine visibility.
  • SecurityRock-solid application security for your peace of mind.
  • Client ToolboxManage projects, contracts, security engagements, and support.
  • Cybersecurity Overview
  • Brand Protection
  • Penetration Testing
  • PTaaS
  • Red Team Operations
  • Incident Response & Advisory
Company
  • About
  • Brand Guide
  • Legal
  • Trust FAQ
Compare
  • Fully Managed Cloud
  • Elestio Alternative
  • Hetzner Alternative
  • Hostinger Alternative
  • SiteGround Alternative
  • OVHcloud Alternative
Cybersecurity
  • Pentest Specialties
  • Web Application Testing
  • API Security Testing
  • Mobile Application Testing
  • Cloud and VPC Security Testing
  • Internal Network Testing
  • External Network Testing
  • Wireless Security Testing
  • Salesforce Security Testing
  • Physical Penetration Testing
  • Phishing and Vishing Simulations
  • IoT Security Testing
  • OT Security Testing
  • AI and LLM Security Testing
  • Industries
  • Financial Services Cybersecurity
  • Healthcare Cybersecurity
  • Government Cybersecurity
  • Education Cybersecurity
  • Manufacturing Cybersecurity
  • Technology Cybersecurity
  • Blockchain and Crypto Cybersecurity
  • Telecommunications Cybersecurity
  • Transportation Cybersecurity
  • Water Utility Cybersecurity
  • Energy Sector Cybersecurity
  • Media Cybersecurity
  • Social Media Platform Cybersecurity
  • Compliance
  • PCI DSS Security Testing
  • HIPAA Security Testing
  • SOC 2 Security Testing
  • GLBA Security Testing
  • CMMC 2.0 / NIST 800-171 Security Testing
  • ISO 27001 Security Testing
  • GDPR Article 32 Security Testing
  • FedRAMP Security Testing
  • Trust Center
  • Security Research
  • Cybersecurity FAQ
  • Certifications
Resources
  • Use Cases
  • Blog
  • Certifications
  • Guides
  • Status
Get Started
  • Contact Sales
  • Pricing
  • Dashboard
EasyCloudify™EasyCloudify™
PricingContact
Log inStart deploying
EasyCloudify™ logoEasyCloudify™

Fully managed cloud infrastructure — deploy in minutes, not days.

Newsletter

The latest news, articles, and resources — delivered weekly.

Product

  • Cloud Platform
  • Marketplace
  • Managed WordPress
  • Mail Hosting
  • Security
  • Brand Protection

Support

  • Open a Ticket
  • Documentation
  • Contact Sales
  • System Status

Company

  • About
  • Brand Guide
  • Global Infrastructure
  • Blog
  • Pricing

Legal

  • Terms of Service
  • Privacy Policy
  • Acceptable Use
  • Trust FAQ
  • All Legal Docs

  • Cloud Platform
  • Marketplace
  • Managed WordPress
  • Mail Hosting
  • Security
  • Brand Protection

  • Open a Ticket
  • Documentation
  • Contact Sales
  • System Status

8 The Green, Suite A, Dover DE 19901, USA
+1 (302) 534-3122

© 2026 EasyCloudify™ LLC. All rights reserved.

Rated on Trustpilot
Terms of ServicePrivacy PolicyAcceptable Use
Security Research

Found in the Field. Fixed at the Source.

Our engineers find vulnerabilities for a living. Most of what we report to clients is about how their systems are built and configured. Sometimes the flaw is in the product itself. When that happens, we take it to the vendor, work through coordinated disclosure, and the issue receives a CVE identifier through MITRE.

12 CVEs to date, across ManageEngine, PRTG Network Monitor, Nagios XI, and Rock RMS. Every one came from real engagement work — not a lab exercise.

Discovered CVEs

12 Vulnerabilities. All From Real Engagements.

Every CVE listed here was discovered during active penetration testing work, not independent research disconnected from real-world environments.

CVE IDProductTypeDescriptionYear
CVE-2026-36748Rock RMSStored XSS → Privilege EscalationStored XSS in Rock RMS that allows a standard user to escalate to administrator when an admin views the malicious user's profile page.2026
CVE-2022-35739PRTG Network MonitorCSS InjectionCSS injection in PRTG Network Monitor via a device's icon/properties field rendered unescaped inside a style tag.2022
CVE-2022-26777ManageEngine Remote Access PlusIDOR (License Details)Insecure direct object reference allowing a Guest user to retrieve license details via the /dcapi/ endpoint.2022
CVE-2022-26653ManageEngine Remote Access PlusIDOR (Domain Details)Insecure direct object reference allowing a Guest user to retrieve connected domain and domain controller details.2022
CVE-2022-25373ManageEngine Support Center PlusStored XSSStored cross-site scripting vulnerability in ManageEngine Support Center Plus.2022
CVE-2022-25245ManageEngine Asset ExplorerInformation LeakageInformation leakage vulnerability in ManageEngine Asset Explorer exposing sensitive system information.2022
CVE-2022-24681ManageEngine ADSelfService PlusStored XSS (Auth Screens)Stored cross-site scripting in ManageEngine AD Self Service Plus authentication screens.2022
CVE-2021-38156Nagios XIStored XSS (Dashboard)Stored cross-site scripting in Nagios XI via dashboard edit functionality.2021
CVE-2021-31813ManageEngine Applications ManagerStored XSS (AD-Imported Names)Stored XSS in ManageEngine Applications Manager via name fields imported from Active Directory.2021
CVE-2021-29643PRTG Network MonitorStored XSSStored cross-site scripting vulnerability in PRTG Network Monitor.2021
CVE-2021-28382ManageEngine Key Manager PlusStored XSS (AD-Imported Fields)Stored XSS in ManageEngine Key Manager Plus via user detail fields imported from Active Directory.2021
CVE-2021-27956ManageEngine ADSelfService PlusStored XSS (Directory Search)Stored XSS in ManageEngine AD Self Service Plus in the email field of directory search results.2021
Disclosure Policy

How We Handle Coordinated Disclosure

We report what we find to the vendor before we publish anything. Closing the hole comes first. The writeup comes second.

01

Report to the vendor

We contact the vendor directly with full technical details before any public disclosure. They get first knowledge, and time to build a fix.

02

Coordinate the timeline

We work with the vendor to understand fix complexity and agree on a disclosure timeline that gives customers time to patch.

03

Confirm the fix

We verify the fix is in place and effective before any public release. A patch that doesn't close the hole isn't a fix.

04

Publish the technical writeup

Only after the fix is confirmed do we publish our technical analysis, so other defenders understand the attack pattern and can validate their own exposure.

Vendor Acknowledgments

GoogleBug Hunters honorable mention

Bypassing a CSP and WAF with Google Tag Manager. An unsafe CSP exemption for GTM turns any script hosted on googletagmanager.com into a usable attack vector.

What This Means for Your Engagement

The engineers who discover vulnerabilities in shipping products are the same ones who test your systems. When something looks unusual, they dig until they understand it — not until a checklist says they can stop.

Original research experience means our testers approach your environment with the same mindset they bring to vendor product analysis: look for what should not be possible.

View Trust Center for full credentials

Put the Research Team on Your Environment

The engineers who find these flaws in shipping products are the same ones who test your systems. Schedule a call to discuss scope and get a fixed estimate.

Our Testing Methodology