Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-77997 1 Yootheme.com 1 Yootheme Pro Extension For Joomla 2026-08-25 N/A
Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions.
CVE-2026-77996 1 Yootheme.com 1 Yootheme Pro Extension For Joomla 2026-08-25 N/A
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
CVE-2026-76613 1 Yootheme.com 1 Yootheme Pro Extension For Joomla 2026-08-23 N/A
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.
CVE-2026-75115 1 Yootheme.com 1 Yootheme Pro Extension For Joomla 2026-08-21 N/A
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.