tribalsystems CVE Vulnerabilities & Metrics

Focus on tribalsystems vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About tribalsystems Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with tribalsystems. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total tribalsystems CVEs: 19
Earliest CVE date: 22 Jan 2018, 01:29 UTC
Latest CVE date: 25 Oct 2023, 18:17 UTC

Latest CVE reference: CVE-2023-44769

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical tribalsystems CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.3

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 6
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS tribalsystems CVEs

These are the five CVEs with the highest CVSS scores for tribalsystems, sorted by severity first and recency.

All CVEs for tribalsystems

CVE-2023-44769 tribalsystems vulnerability CVSS: 0 25 Oct 2023, 18:17 UTC

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.

CVE-2023-44771 tribalsystems vulnerability CVSS: 0 06 Oct 2023, 13:15 UTC

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.

CVE-2023-44770 tribalsystems vulnerability CVSS: 0 06 Oct 2023, 13:15 UTC

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.

CVE-2023-39578 tribalsystems vulnerability CVSS: 0 28 Aug 2023, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.

CVE-2022-44136 tribalsystems vulnerability CVSS: 0 30 Nov 2022, 15:15 UTC

Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

CVE-2022-4231 tribalsystems vulnerability CVSS: 0 30 Nov 2022, 12:15 UTC

A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214589 was assigned to this vulnerability.

CVE-2022-44073 tribalsystems vulnerability CVSS: 0 16 Nov 2022, 16:15 UTC

Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.

CVE-2022-44071 tribalsystems vulnerability CVSS: 0 16 Nov 2022, 16:15 UTC

Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.

CVE-2022-44070 tribalsystems vulnerability CVSS: 0 16 Nov 2022, 16:15 UTC

Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.

CVE-2022-44069 tribalsystems vulnerability CVSS: 0 16 Nov 2022, 16:15 UTC

Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.

CVE-2020-36608 tribalsystems vulnerability CVSS: 0 02 Nov 2022, 19:15 UTC

A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this issue is some unknown functionality of the file admin_organizer.js of the component Error Log Module. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is dfd0afacb26c3682a847bea7b49ea440b63f3baa. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-212816.

CVE-2021-42171 tribalsystems vulnerability CVSS: 6.5 14 Mar 2022, 15:15 UTC

Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.

CVE-2021-41952 tribalsystems vulnerability CVSS: 3.5 14 Mar 2022, 15:15 UTC

Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicious files to victims and steals victim's cookie leads to account takeover. The person viewing the image of a contact can be victim of XSS.

CVE-2022-23043 tribalsystems vulnerability CVSS: 6.5 24 Feb 2022, 15:15 UTC

Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run commands on the server.

CVE-2021-26830 tribalsystems vulnerability CVSS: 6.4 16 Apr 2021, 18:15 UTC

SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.

CVE-2021-27673 tribalsystems vulnerability CVSS: 3.5 15 Apr 2021, 14:15 UTC

Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "cID" parameter when creating a new HTML component.

CVE-2021-27672 tribalsystems vulnerability CVSS: 4.0 15 Apr 2021, 14:15 UTC

SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the "cID" parameter when creating a new HTML component.

CVE-2018-18420 tribalsystems vulnerability CVSS: 6.8 19 Oct 2018, 22:29 UTC

Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI.

CVE-2018-5960 tribalsystems vulnerability CVSS: 6.5 22 Jan 2018, 01:29 UTC

Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module.