« Back to list

Yootheme

Yootheme PRO: vulnerabilities and CVEs

Yootheme PRO has 3 published vulnerabilities, 3 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months3
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-77997Medium (5.1)0.39%—Aug 25, 2026
Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about…
CVE-2026-77996High (7.5)0.42%—Aug 25, 2026
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
CVE-2026-76613High (8.6)0.37%—Aug 21, 2026
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1059.007 JavaScript1
  3. T1190 Exploit Public-Facing Application1
  4. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Yootheme