« Volver al listado

Yootheme

Yootheme ZOO: vulnerabilidades y CVE

Yootheme ZOO tiene 8 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses8
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77028Media (5.3)0.41%—21 ago 2026
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
CVE-2026-76612Alta (8.6)0.44%—21 ago 2026
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.
CVE-2026-76611Media (6.9)0.50%—21 ago 2026
Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.
CVE-2026-77029Media (4.6)0.21%—21 ago 2026
Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
CVE-2026-76610Media (6.9)0.22%—20 ago 2026
Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.
CVE-2026-75114Media (5.1)0.41%—19 ago 2026
Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation.
CVE-2026-74804Crítica (9.3)0.39%—19 ago 2026
Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as…
CVE-2026-74803Crítica (10)0.43%—19 ago 2026
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1005 Data from Local System1
  3. T1059.007 JavaScript1
  4. T1189 Drive-by Compromise1
  5. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Yootheme