{"id":"CVE-2026-79035","title":"A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL …","summary":"A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL …","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"published":"2026-09-11","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79035","references":[{"url":"https://github.com/nikolas-ch/CVEs/blob/main/ZetaMarketingPlatform/ReflectedXSS/ReflectedXSS.txt","label":"cve@mitre.org"},{"url":"https://github.com/nikolas-ch/CVEs/tree/main/ZetaMarketingPlatform/ReflectedXSS","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00188,"epssPercentile":0.08679,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T15:20:26.288947Z"},"ingestedAt":"2026-09-14T10:09:58.905Z","slug":"CVE-2026-79035","body":"## Overview\n\nA reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203815,"id":"CVE-2026-79035","ts":1789486794683,"field":"cvss","old":null,"new":"6.1"},{"seq":203814,"id":"CVE-2026-79035","ts":1789486794683,"field":"severity","old":"none","new":"medium"}]}