PatchSiren

yootheme.com CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL yootheme.com CVE published 2026-08-21

CVE-2026-76613

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T13:18:20.140Z and has not been modified since then. This critical SQL injection vulnerability in YOOtheme Pro 1.0.0-5.0.40 allows contributor-level users to inject content into SQL queries, potentially leading to data breaches or system compromise. Evidence is limited; primary official records in [truncated]

MEDIUM yootheme.com CVE published 2026-08-21

CVE-2026-77029

The CVE-2026-77029 vulnerability affects Joomla Extension - yootheme.com, specifically versions of Zoo prior to 4.1.66. The vulnerability is caused by missing CSRF tokens on front-end state changes. This could allow an attacker to perform unauthorized actions on the affected system. Administrators and users of Joomla Extension - yootheme.com, particularly those using versions of Zoo prior to 4.1.66, shoul [truncated]