VYPR

Zenario

by Tribalsystems

Source repositories

CVEs (23)

  • CVE-2024-34461CriMay 4, 2024
    risk 0.57cvss 9.8epss 0.01

    Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.

  • CVE-2022-44136CriNov 30, 2022
    risk 0.57cvss 9.8epss 0.01

    Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

  • CVE-2018-18420HigOct 19, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI.

  • CVE-2018-5960HigJan 22, 2018
    risk 0.57cvss 8.8epss 0.01

    Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module.

  • CVE-2021-26830CriApr 16, 2021
    risk 0.56cvss 9.1epss 0.05

    SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.

  • CVE-2021-42171HigMar 14, 2022
    risk 0.40cvss 7.2epss 0.03

    Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.

  • CVE-2022-23043HigFeb 24, 2022
    risk 0.40cvss 7.2epss 0.01

    Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run…

  • CVE-2024-34460MedMay 4, 2024
    risk 0.35cvss 6.5epss 0.01

    The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)

  • CVE-2023-44769MedOct 25, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.

  • CVE-2023-44771MedOct 6, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.

  • CVE-2023-44770MedOct 6, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.

  • CVE-2022-44073MedNov 16, 2022
    risk 0.35cvss 5.4epss 0.00

    Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.

  • CVE-2022-44071MedNov 16, 2022
    risk 0.35cvss 5.4epss 0.00

    Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.

  • CVE-2022-44070MedNov 16, 2022
    risk 0.35cvss 5.4epss 0.00

    Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.

  • CVE-2022-44069MedNov 16, 2022
    risk 0.35cvss 5.4epss 0.00

    Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.

  • CVE-2024-45964MedOct 2, 2024
    risk 0.31cvss 4.8epss 0.00

    Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.

  • CVE-2024-45960MedOct 2, 2024
    risk 0.31cvss 4.8epss 0.00

    Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.

  • CVE-2023-39578MedAug 28, 2023
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.

  • CVE-2021-27673MedApr 15, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "cID" parameter when creating a new HTML component.

  • CVE-2022-4231MedNov 30, 2022
    risk 0.27cvss 4.2epss 0.00

    A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The…

Page 1 of 2