Unauthenticated File Upload Vulnerability in Joomla Extension YOOtheme Zoo
CVE-2026-74803

10CRITICAL

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-74803?

The YOOtheme Zoo extension prior to version 4.1.64 for Joomla contains a vulnerability allowing unauthenticated users to upload arbitrary files. This occurs due to the image element accepting files whose Content-Type is within the image MIME group. Exploitation of this vulnerability could lead to file manipulation or unauthorized access to the server, making it critical for users to update their installations to the latest version to mitigate risks.

Affected Version(s)

Zoo extension for Joomla 1.0.0-4.1.63

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.