Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2023-44769

Disclosure Date: October 25, 2023 (last updated November 02, 2023)
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.
Attacker Value
Unknown

CVE-2023-44771

Disclosure Date: October 06, 2023 (last updated October 09, 2023)
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.
Attacker Value
Unknown

CVE-2023-44770

Disclosure Date: October 06, 2023 (last updated October 09, 2023)
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.
Attacker Value
Unknown

CVE-2023-39578

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.
Attacker Value
Unknown

CVE-2022-44136

Disclosure Date: November 30, 2022 (last updated October 08, 2023)
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
Attacker Value
Unknown

CVE-2022-4231

Disclosure Date: November 30, 2022 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214589 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-44069

Disclosure Date: November 16, 2022 (last updated December 22, 2024)
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.
Attacker Value
Unknown

CVE-2022-44073

Disclosure Date: November 16, 2022 (last updated December 22, 2024)
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.
Attacker Value
Unknown

CVE-2022-44071

Disclosure Date: November 16, 2022 (last updated December 22, 2024)
Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.
Attacker Value
Unknown

CVE-2022-44070

Disclosure Date: November 16, 2022 (last updated December 22, 2024)
Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.