SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75115

HIGH · CVSS 7 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The YOOtheme Pro extension for Joomla versions 2.3.0 to 5.0.40 is vulnerable to a glob-based pattern attack that permits authenticated, privileged users to read arbitrary files on the server. This vulnerability could lead to unauthorized access to sensitive information, potentially compromising the integrity and confidentiality of the affected system. Organizations using this extension should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-75115
Severity
HIGH
CVSS
7
EPSS
0.31%

Original NVD Description

Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.