PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77996 yootheme.com CVE debrief

CVE-2026-77996 is a high-severity vulnerability in YOOtheme Pro, a Joomla extension, affecting versions 1.0.0-5.0.41. The vulnerability is caused by a lack of escaping in the location custom field, leading to a stored XSS vector. This CVE was published on 2026-08-25T12:16:25.973Z and was last modified on 2026-09-23T13:10:00.153Z. Defenders should assess exposure and prioritize patching or mitigation. The vulnerability's impact is limited to authenticated, privileged users, but could still lead to significant disruption and content injection.

Vendor
yootheme.com
Product
YOOtheme Pro extension for Joomla
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-09-23
Advisory published
2026-08-25
Advisory updated
2026-09-23

Who should care

Defenders responsible for Joomla installations using YOOtheme Pro should assess exposure and prioritize patching or mitigation. This includes administrators, security teams, and IT personnel managing Joomla sites with YOOtheme Pro extensions. They should verify exposure, apply patches, and monitor for potential exploitation attempts.

Why it matters

CVE-2026-77996 is a high-severity stored XSS vulnerability in YOOtheme Pro for Joomla. Defenders should verify exposure, prioritize patching, and monitor for exploitation attempts. The vulnerability's impact is limited to authenticated, privileged users, but could still lead to significant disruption and content injection.

  • Potential for attacker-controlled content injection
  • Possible disruption of Joomla site functionality
  • Risk of user session compromise
  • Need for verification of exposure and patch application

Technical summary

The vulnerability is caused by a lack of escaping in the location custom field of YOOtheme Pro, a Joomla extension, leading to a stored XSS vector. This affects versions 1.0.0-5.0.41 and has a CVSS score of 7.5. The vulnerability is limited to authenticated, privileged users but could still lead to significant disruption and content injection. Defenders should prioritize verifying exposure of Joomla installations using YOOtheme Pro and apply patches or mitigations as available.

Defensive priority

Defenders should prioritize verifying exposure of Joomla installations using YOOtheme Pro and apply patches or mitigations as available.

Recommended defensive actions

  • Verify Joomla installations for YOOtheme Pro usage and assess exposure
  • Apply patches or mitigations as available from the vendor
  • Monitor for potential exploitation attempts

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.5 and CWE-79 classification. Evidence is limited to public CVE and NVD information. Defenders should verify exposure using official channels and apply patches or mitigations as available. The vulnerability affects YOOtheme Pro versions 1.0.0-5.0.41.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77996 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77996

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77996 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77996

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.