Joomla扩展 - yootheme.com - Zoo 版本低于 4.1.66 时,通过提交重定向参数可导致反射型XSS和开放重定向漏洞
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| yootheme.com | Zoo extension for Joomla | 1.0.0-4.1.65 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| yootheme.com | Zoo extension for Joomla | 1.0.0-4.1.65 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76613 | 8.6 HIGH | Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro |
| CVE-2026-76612 | 8.6 HIGH | Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in |
| CVE-2026-75115 | 7.0 HIGH | Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOthem |
| CVE-2026-76611 | 6.9 MEDIUM | Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gall |
| CVE-2026-77029 | 4.6 MEDIUM | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < |
No comments yet