Unauthenticated Directory Listing in Joomla Extension by Yootheme
CVE-2026-76611

6.9MEDIUM

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-76611?

A security issue exists in the Yootheme Zoo extension for Joomla, which allows unauthenticated users to access and list arbitrary directories through the Gallery element. This vulnerability can expose sensitive information or files stored on the server, posing a security risk for websites using affected versions of the Zoo extension. It is essential for users to upgrade to version 4.1.66 or later to mitigate this vulnerability and secure their installations.

Affected Version(s)

Zoo extension for Joomla 1.0.0-4.1.65

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.