Authenticated Information Disclosure in YOOtheme Pro - Joomla Extension
CVE-2026-77997

5.1MEDIUM

Key Information:

Vendor
CVE Published:
25 August 2026

What is CVE-2026-77997?

The YOOtheme Pro extension for Joomla contains a vulnerability allowing users with editing permissions for the com_template component to bypass access controls and retrieve sensitive information about arbitrary modules. This flaw results from a missing access check, exposing data to unauthorized users who should not have permissions for the com_modules component.

Affected Version(s)

YOOtheme Pro extension for Joomla 1.0.0-5.0.41

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.