Unauthenticated SQL Injection in Joomla Extension by YOOtheme
CVE-2026-74804
9.3CRITICAL
What is CVE-2026-74804?
An unauthenticated SQL injection vulnerability has been identified in the Zoo component of YOOtheme's Joomla Extension. The issue resides in the ItemController::element() method, where the 'filter_type' request value is improperly interpolated into the SQL query. Consequently, this allows an attacker to manipulate the query using unescaped input values, potentially leading to unauthorized access to the database and retrieval of sensitive information. Users are advised to upgrade to a secure version to mitigate this vulnerability.
Affected Version(s)
Zoo extension for Joomla 1.0.0-4.1.63
