Tribalsystems develops Zenario, a content management and website-building platform whose vulnerability footprint, despite a narrow product scope, registers among the more prominent in the landscape due to the platform's wide deployment across web properties. Vulnerabilities affecting the vendor lean toward serious outcomes, with a meaningful share reaching critical severity, and concentrate persistently in application-layer input-handling weaknesses: cross-site scripting, SQL injection, unsafe file uploads, and cross-site request forgery reflect the CMS's exposure to user-supplied content and web-form processing. Defenders deploying or maintaining Zenario should prioritize input validation and output-encoding hardening, inventory instances across their web infrastructure, and treat updates as part of routine web-application patch cycles. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tribalsystems over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26830CRITICAL SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php | Apr 16, 2021 | 9.1 | 40 | NO | YES |
CVE-2022-44136CRITICAL Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE). | Nov 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-18420HIGH Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpane | Oct 19, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-5960HIGH Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module. | Jan 22, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-42171HIGH Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse loc | Mar 14, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-23043HIGH Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can uploa | Feb 24, 2022 | 7.2 | 24 | NO | NO |
CVE-2020-36608MEDIUM A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer | Nov 2, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-4231MEDIUM A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember M | Nov 30, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-44073MEDIUM Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts. | Nov 16, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-44071MEDIUM Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile. | Nov 16, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tribalsystems.
Media articles that mention a CVE ID that affects a product developed by Tribalsystems — matched by CVE ID, not by vendor name.