MEDIUM
YOOtheme
CVE published 2026-08-21
CVE-2026-76611
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T13:18:19.850Z and has not been modified since then. This vulnerability affects Joomla Extension - yootheme.com, specifically versions prior to 4.1.66, and allows for unauthenticated arbitrary directory listing via the Gallery element in Zoo. The CVSS score of 6.9 indicates a medium severity level [truncated]