SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77997

MEDIUM · CVSS 5.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The YOOtheme Pro extension for Joomla is vulnerable due to a missing access check, allowing users with template editing permissions to access sensitive information about arbitrary modules without the necessary module permissions. This could lead to unauthorized information disclosure, potentially exposing critical data to users who should not have access. Joomla site administrators and developers using YOOtheme Pro should prioritize this vulnerability to mitigate the risk of data leaks.

CVE
CVE-2026-77997
Severity
MEDIUM
CVSS
5.1
EPSS
0.23%

Original NVD Description

Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions.