CVE-2026-79035
A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.
- Published Sep 11, 2026
- CVSS 6.1 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)