CVE-2026-79035

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.

Published 2026-09-11. Last modified 2026-09-22.