CVE-2026-79035

NONE EPSS 0.15%
Updated Sep 11, 2026
Parameter Value
Public PoC No

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.