SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76612

HIGH · CVSS 8.6 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla Extension from yootheme.com is vulnerable to unauthenticated stored cross-site scripting (XSS) due to inadequate escaping of user-controlled input in comments and field elements in versions prior to 4.1.66. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of other users, potentially compromising their data and session integrity. Organizations using this extension should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-76612
Severity
HIGH
CVSS
8.6
EPSS
0.35%

Original NVD Description

Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.