Joomla 扩展 - yootheme.com - Zoo < 4.1.64 版本中,ItemController::element() 方法存在未认证的 SQL 注入漏洞。请求参数 filter_type 的值被直接拼接进 SQL 查询语句中,表现为 a.type = "..." 和 a.type IN ("...") 的形式,且未进行任何引号转义或数据过滤处理。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| yootheme.com | Zoo extension for Joomla | 1.0.0-4.1.63 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yootheme.com | Zoo extension for Joomla | 1.0.0-4.1.63 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74803 | 10.0 CRITICAL | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 |
| CVE-2026-75114 | 5.1 MEDIUM | Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate( |
No comments yet