PatchSiren

YOOtheme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM YOOtheme CVE published 2026-08-21

CVE-2026-76611

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T13:18:19.850Z and has not been modified since then. This vulnerability affects Joomla Extension - yootheme.com, specifically versions prior to 4.1.66, and allows for unauthenticated arbitrary directory listing via the Gallery element in Zoo. The CVSS score of 6.9 indicates a medium severity level [truncated]