Known Vulnerabilities for Zoo Extension For Joomla by Yootheme.com
Listed below are 10 of the newest known vulnerabilities associated with "Zoo Extension For Joomla" by "Yootheme.com".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-78374 json | Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-78303 json | Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-78302 json | Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-78085 json | Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery managemen... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-78084 json | Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-78083 json | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Pro... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-78082 json | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-78080 json | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in que... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-78079 json | Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect pa... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-78078 json | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image upl... | Not Provided | 2026-08-31 | 2026-08-31 |