Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yootheme.com | YOOtheme Pro extension for Joomla | 2.3.0-5.0.40 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76613 | 9.2 CRITICAL | Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro |
| CVE-2026-76612 | 8.6 HIGH | Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in |
| CVE-2026-76611 | 6.9 MEDIUM | Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gall |
| CVE-2026-77028 | 5.3 MEDIUM | Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redir |
| CVE-2026-77029 | 4.6 MEDIUM | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < |
No comments yet