Zenario v7.1 - v7.6 has SQL injection via the Name input field of organizer.php or admin_boxes.ajax.php in the Categories - Edit module.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.1"
},
{
"introduced": "0"
},
{
"last_affected": "7.2"
},
{
"introduced": "0"
},
{
"last_affected": "7.3"
},
{
"introduced": "0"
},
{
"last_affected": "7.4"
},
{
"introduced": "0"
},
{
"last_affected": "7.5"
}
]
}