tribalsystems/zenario Security Advisories for 8.7 (19)
- 
                        [LOW] Zenario Cross Site Scripting in the Image libraryPKSA-626r-ptwv-5msz CVE-2024-45964 GHSA-2cc5-429x-p387 Affected version: <=9.7.61188 Reported by: 
 GitHub
- 
                        [LOW] Zenario allows authenticated admin users to upload PDF files containing malicious codePKSA-jm4c-kd3j-5hgr CVE-2024-45960 GHSA-3636-hx62-pv26 Affected version: <=9.7.61188 Reported by: 
 GitHub
- 
                        [CRITICAL] Zenario uses Twig filters insecurely in the Twig Snippet pluginPKSA-2vff-jckp-41b9 CVE-2024-34461 GHSA-hr2r-w6wc-25pv Affected version: <9.5.60437 Reported by: 
 GitHub
- 
                        [MEDIUM] Zenario's Tree Explorer tool from Organizer affected by Cross-site ScriptingPKSA-7y52-wyc4-jh5d CVE-2024-34460 GHSA-7qwj-gcjf-828f Affected version: <9.5.60602 Reported by: 
 GitHub
- 
                        [MEDIUM] Zenario CMS Cross-site Scripting vulnerabilityPKSA-sgtd-47vh-v7xk CVE-2023-44769 GHSA-8g87-73vq-443p Affected version: <=9.4.59197 Reported by: 
 GitHub
- 
                        [MEDIUM] Zenario CMS Cross-site Scripting vulnerabilityPKSA-wj4z-2892-4z7j CVE-2023-44771 GHSA-6cxv-27r2-fp3m Affected version: <=9.4.59197 Reported by: 
 GitHub
- 
                        [MEDIUM] Zenario CMS Cross-site Scripting vulnerabilityPKSA-1xsc-5sr6-rvqw CVE-2023-44770 GHSA-mr4w-7vm9-cgqx Affected version: <=9.4.59197 Reported by: 
 GitHub
- 
                        [CRITICAL] Zenario CMS is vulnerable to Remote Code Execution (RCE).PKSA-r3db-vqz5-y73v CVE-2022-44136 GHSA-4p38-rc98-cr39 Affected version: <9.0.57473 Reported by: 
 GitHub
- 
                        [MEDIUM] Tribal Systems Zenario CMS vulnerable to Session FixationPKSA-kr7w-3swh-1np4 CVE-2022-4231 GHSA-6657-9743-4mc6 Affected version: <=9.3.57595 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in ZenarioPKSA-m58d-b4jx-rskk CVE-2022-44070 GHSA-f454-jm6x-56q6 Affected version: <=9.3.57186 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in ZenarioPKSA-skk6-b7wm-3vk6 CVE-2022-44073 GHSA-gmf5-q34v-vwvp Affected version: <=9.3.57186 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in ZenarioPKSA-ksv4-pxr6-sf1s CVE-2022-44071 GHSA-j43m-4pxc-hmqj Affected version: <=9.3.57186 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in ZenarioPKSA-5bxv-x652-p1vq CVE-2022-44069 GHSA-r9xx-4cmv-856x Affected version: <=9.3.57186 Reported by: 
 GitHub
- 
                        [CRITICAL] SQL Injection in tribalsystems/zenarioPKSA-q8d1-1bp6-gjp2 CVE-2021-26830 GHSA-w4f3-7f7c-x652 Affected version: <8.8.53370 Reported by: 
 GitHub
- 
                        [MEDIUM] Cross-site Scripting in Zenario CMSPKSA-ctkk-ks6k-nhws CVE-2021-41952 GHSA-x8wj-cqmp-3wmm Affected version: <=9.0.54156 Reported by: 
 GitHub
- 
                        [CRITICAL] Unrestricted Upload of File with Dangerous Type in Zenario CMSPKSA-7nc3-zf98-kc29 CVE-2021-42171 GHSA-rgg3-3wh7-w935 Affected version: <=9.0.54156 Reported by: 
 GitHub
- 
                        [HIGH] File upload restriction bypass in Zenario CMSPKSA-b6mz-47rp-w3c4 CVE-2022-23043 GHSA-6r86-2jm9-9mh4 Affected version: <9.2.55826 Reported by: 
 GitHub
- 
                        [MEDIUM] SQL Injection in tribalsystems/zenarioPKSA-pvjm-gvbd-5smh CVE-2021-27672 GHSA-gxcm-36qw-j29v Affected version: <8.8.53370 Reported by: 
 GitHub
- 
                        [MEDIUM] reflected XSS in tribalsystems/zenarioPKSA-sqfw-99rk-f1bg CVE-2021-27673 GHSA-8hcm-jj4x-4gmr Affected version: <8.8.53370 Reported by: 
 GitHub