PatchSiren cyber security CVE debrief
CVE-2026-77996 yootheme.com CVE debrief
CVE-2026-77996 is a high-severity vulnerability in YOOtheme Pro, a Joomla extension, affecting versions 1.0.0-5.0.41. The vulnerability is caused by a lack of escaping in the location custom field, leading to a stored XSS vector. This CVE was published on 2026-08-25T12:16:25.973Z and was last modified on 2026-09-23T13:10:00.153Z. Defenders should assess exposure and prioritize patching or mitigation. The vulnerability's impact is limited to authenticated, privileged users, but could still lead to significant disruption and content injection.
- Vendor
- yootheme.com
- Product
- YOOtheme Pro extension for Joomla
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-23
Who should care
Defenders responsible for Joomla installations using YOOtheme Pro should assess exposure and prioritize patching or mitigation. This includes administrators, security teams, and IT personnel managing Joomla sites with YOOtheme Pro extensions. They should verify exposure, apply patches, and monitor for potential exploitation attempts.
Why it matters
CVE-2026-77996 is a high-severity stored XSS vulnerability in YOOtheme Pro for Joomla. Defenders should verify exposure, prioritize patching, and monitor for exploitation attempts. The vulnerability's impact is limited to authenticated, privileged users, but could still lead to significant disruption and content injection.
- Potential for attacker-controlled content injection
- Possible disruption of Joomla site functionality
- Risk of user session compromise
- Need for verification of exposure and patch application
Technical summary
The vulnerability is caused by a lack of escaping in the location custom field of YOOtheme Pro, a Joomla extension, leading to a stored XSS vector. This affects versions 1.0.0-5.0.41 and has a CVSS score of 7.5. The vulnerability is limited to authenticated, privileged users but could still lead to significant disruption and content injection. Defenders should prioritize verifying exposure of Joomla installations using YOOtheme Pro and apply patches or mitigations as available.
Defensive priority
Defenders should prioritize verifying exposure of Joomla installations using YOOtheme Pro and apply patches or mitigations as available.
Recommended defensive actions
- Verify Joomla installations for YOOtheme Pro usage and assess exposure
- Apply patches or mitigations as available from the vendor
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.5 and CWE-79 classification. Evidence is limited to public CVE and NVD information. Defenders should verify exposure using official channels and apply patches or mitigations as available. The vulnerability affects YOOtheme Pro versions 1.0.0-5.0.41.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77996 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77996
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77996 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77996
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.yootheme.com/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.