Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

yootheme.com — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting yootheme.com. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page provides a comprehensive vulnerability aggregation report for the vendor yootheme.com, focusing on software weaknesses and security advisories. It collects data regarding various vulnerability types, including cross-site scripting, SQL injection, and authentication bypasses, covering reports published from 2015 to the present. Users can track the vendor's security advisory history to understand their response times and patch management practices. The page allows visitors to investigate specific weakness classes associated with the vendor's products, such as YOOtheme Pro and Joomla templates. By analyzing this data, security professionals can assess the overall security posture of yootheme.com's ecosystem. Readers can look up the vulnerability history of specific products to identify recurring issues or critical flaws that may require immediate attention. The information helps in evaluating risk levels and planning mitigation strategies for systems relying on these components. This resource serves as a centralized hub for auditing and security research, providing transparency into past incidents and current threats. It does not offer promotional content or marketing materials but focuses strictly on factual security data. The aggregation helps organizations make informed decisions about software procurement and deployment by highlighting potential risks associated with the vendor's offerings.

CVE ID Title CVSS Severity Published
CVE-2026-76612 Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 — Zoo extension for Joomla CWE-79 8.6 High 2026-08-21
CVE-2026-76611 Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66 — Zoo extension for Joomla CWE-22 6.9 Medium 2026-08-21
CVE-2026-75115 Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 — YOOtheme Pro extension for Joomla CWE-22 7.0 High 2026-08-21
CVE-2026-76613 Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 — YOOtheme Pro extension for Joomla CWE-89 8.6 High 2026-08-21
CVE-2026-77028 Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 — Zoo extension for Joomla CWE-79 5.3 Medium 2026-08-21
CVE-2026-77029 Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66 — Zoo extension for Joomla CWE-352 4.6 Medium 2026-08-21
CVE-2026-76610 Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 — Zoo extension for Joomla CWE-352 6.9 Medium 2026-08-20
CVE-2026-74803 Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 — Zoo extension for Joomla CWE-434 10.0 Critical 2026-08-19
CVE-2026-75114 Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 — Zoo extension for Joomla CWE-601 5.1 Medium 2026-08-19
CVE-2026-74804 Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 — Zoo extension for Joomla CWE-89 9.3 Critical 2026-08-19

This page lists every published CVE security advisory associated with yootheme.com. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.