Unauthenticated Stored XSS in Joomla Extension by Yootheme
CVE-2026-76612

8.6HIGH

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-76612?

The Joomla extension developed by Yootheme is susceptible to an unauthenticated stored XSS vulnerability. This arises from insufficient escaping of user-provided input in comments and user-controlled field elements, making it possible for attackers to inject malicious scripts. If exploited, this vulnerability allows attackers to execute arbitrary JavaScript in the context of other users, leading to potential data theft, user session hijacking, or other malicious activities.

Affected Version(s)

Zoo extension for Joomla 1.0.0-4.1.65

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.