Joomla 扩展 - yootheme.com - Zoo < 4.1.66 版本中,由于未认证的存储型跨站脚本攻击(Stored XSS)漏洞,可通过用户可控字段进行攻击。在评论和用户提供的字段元素中,用户输入的未进行转义处理,从而导致存储型 XSS 攻击向量的存在。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| yootheme.com | Zoo extension for Joomla | 1.0.0-4.1.65 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yootheme.com | Zoo extension for Joomla | 1.0.0-4.1.65 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76613 | 8.6 HIGH | Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro |
| CVE-2026-75115 | 7.0 HIGH | Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOthem |
| CVE-2026-76611 | 6.9 MEDIUM | Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gall |
| CVE-2026-77028 | 5.3 MEDIUM | Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redir |
| CVE-2026-77029 | 4.6 MEDIUM | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < |
No comments yet