Unauthenticated SQL Injection in Joomla Extension by YOOtheme
CVE-2026-74804

9.3CRITICAL

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-74804?

An unauthenticated SQL injection vulnerability has been identified in the Zoo component of YOOtheme's Joomla Extension. The issue resides in the ItemController::element() method, where the 'filter_type' request value is improperly interpolated into the SQL query. Consequently, this allows an attacker to manipulate the query using unescaped input values, potentially leading to unauthorized access to the database and retrieval of sensitive information. Users are advised to upgrade to a secure version to mitigate this vulnerability.

Affected Version(s)

Zoo extension for Joomla 1.0.0-4.1.63

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.