Known Vulnerabilities for YOOtheme Pro Extension For Joomla by Yootheme.com
Listed below are 10 of the newest known vulnerabilities associated with "YOOtheme Pro Extension For Joomla" by "Yootheme.com".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77029 json | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66 | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-77028 json | Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76613 json | Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection all... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76612 json | Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76611 json | Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66. | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76610 json | Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-75115 json | Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-75114 json | Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer req... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-74804 json | Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_typ... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-74803 json | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary... | Not Provided | 2026-08-19 | 2026-08-20 |