CVE-2024-34461: Tribalsystems Zenario
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.
Affected products
- Tribalsystems Zenario: before 9.5.60437 (fixed in 9.5.60437)
Published 2024-05-04. Last modified 2026-06-17.