CyberRota Analysis
AI-GeneratedThe YOOtheme Pro extension for Joomla versions 1.0.0 to 5.0.41 is vulnerable to an authenticated, privileged stored cross-site scripting (XSS) attack due to inadequate escaping in the location custom field. This flaw allows attackers with valid credentials to inject malicious scripts, potentially compromising user data and session integrity. Joomla administrators and web developers using this extension should prioritize applying security updates to mitigate the risk of exploitation.
CVE
CVE-2026-77996
Severity
HIGH
CVSS
7.5
EPSS
0.25%
Original NVD Description
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.