PatchSiren

yootheme.com CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM yootheme.com CVE published 2026-08-25

CVE-2026-77997

A Joomla Extension, YOOtheme Pro, has a missing access check allowing users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions. This issue affects versions 1.0.0-5.0.41. The vulnerability allows authenticated users to access sensitive module information, potentially leading to unauthorized access or misuse of module data. Joom [truncated]

HIGH yootheme.com CVE published 2026-08-25

CVE-2026-77996

Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 due to lack of escaping in the location custom field. This vulnerability allows attackers to inject malicious code, potentially leading to code injection, data theft or modification, and privilege escalation in Joomla installations. Defenders should assess exposure and prioritize patching to mitigate these risks. The vulnerability has a CVS [truncated]

MEDIUM yootheme.com CVE published 2026-08-21

CVE-2026-77028

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T13:18:20.280Z and has not been modified since then. This vulnerability affects Joomla sites with the Zoo extension installed, particularly versions less than 4.1.66. It allows for reflected XSS and open redirect attacks via the submission redirect parameter, potentially enabling attackers to redi [truncated]

HIGH yootheme.com CVE published 2026-08-21

CVE-2026-76613

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T13:18:20.140Z and has not been modified since then. This critical SQL injection vulnerability in YOOtheme Pro 1.0.0-5.0.40 allows contributor-level users to inject content into SQL queries, potentially leading to data breaches or system compromise. Evidence is limited; primary official records in [truncated]

HIGH yootheme.com CVE published 2026-08-21

CVE-2026-76612

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T13:18:19.990Z and has not been modified since then. The Joomla Extension - yootheme.com is vulnerable to unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66. User-supplied input in comments and user-supplied field elements weren't escaped, leading to a stored XSS vector. This vu [truncated]

MEDIUM yootheme.com CVE published 2026-08-21

CVE-2026-77029

The CVE-2026-77029 vulnerability affects Joomla Extension - yootheme.com, specifically versions of Zoo prior to 4.1.66. The vulnerability is caused by missing CSRF tokens on front-end state changes. This could allow an attacker to perform unauthorized actions on the affected system. Administrators and users of Joomla Extension - yootheme.com, particularly those using versions of Zoo prior to 4.1.66, shoul [truncated]