{"id":"CVE-2021-26830","details":"SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.","aliases":["GHSA-w4f3-7f7c-x652"],"modified":"2026-07-08T05:58:59.520882806Z","published":"2021-04-16T18:15:13.403Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"8.8.52729"},{"last_affected":"8.8.52729"}],"source":"CPE_STRING","vendor_product":"tribalsystems:zenario","cpes":["cpe:2.3:a:tribalsystems:zenario:8.8.52729:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://github.com/TribalSystems/Zenario/releases/tag/8.8.53370"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tribalsystems/zenario","events":[{"introduced":"0"},{"fixed":"2c82a4d126c8446106347ef603b157f2d4175fd1"}],"database_specific":{"source":"REFERENCES"}}],"versions":["8.8","8.7","8.6.51342","8.5.51340","8.4.50565","8.5.50837","8.5.50567","8.3.50564","8.3.48583","8.3.47997","8.2.47992","8.2.47369","8.2.47180","8.2.46614","8.0.45529","8.2.46436","8.1.46433","8.1.46089","8.1.45698","8.1.45530","7.7.44223","8.0.45250","8.0.45032","8.0.44521","8.0.44294","8.0.44273","8.0.44237","7.7.42990","7.7.42963","7.7.42682","7.6.42085","7.6.41633","7.6.41504","7.5.41499","7.5.41006","7.5.40440","7.5.0","7.4.4","7.4.3","7.2.3","7.4.2","7.4.1","7.4.0","7.3.0","7.1.2","7.2.2","7.0.7e","7.2.1","7.2.0","7.1.1","7.1.0","7.0.7d","7.0.7c","7.0.7b","7.0.7a","7.0.6b","7.0.4b","7.0.3a","7.0.2e","7.0.6a","7.0.5c","7.0.5b"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-26830.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}