Unauthenticated File Upload Vulnerability in Joomla Extension YOOtheme Zoo
CVE-2026-74803
10CRITICAL
What is CVE-2026-74803?
The YOOtheme Zoo extension prior to version 4.1.64 for Joomla contains a vulnerability allowing unauthenticated users to upload arbitrary files. This occurs due to the image element accepting files whose Content-Type is within the image MIME group. Exploitation of this vulnerability could lead to file manipulation or unauthorized access to the server, making it critical for users to update their installations to the latest version to mitigate risks.
Affected Version(s)
Zoo extension for Joomla 1.0.0-4.1.63
