Zenario v7.1 - v7.6 has SQL injection via the Name input field of organizer.php or admin_boxes.ajax.php in the Categories - Edit module.
Name
Categories - Edit
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-5960.json"