Vulnerabilidades em yootheme.com
12 resultadosAnálise Vexday
YooTheme apresenta 10 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e ativa do fornecedor. Embora 3 sejam críticas (CVSS), nenhuma está sob exploração ativa documentada, e a fraqueza dominante é traversal de diretório (CWE-22), tipicamente contornável com patches. O risco moderado recomenda monitoramento próximo e aplicação tempestiva de atualizações.
CVE-2026-76612HIGHJoomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66EPSS 0.3%CVE-2026-76611MEDIUMJoomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66EPSS 0.3%CVE-2026-75115HIGHJoomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40EPSS 0.3%CVE-2026-74803CRITICALJoomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64EPSS 0.3%CVE-2026-75114MEDIUMJoomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64EPSS 0.3%CVE-2026-76613HIGHJoomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40EPSS 0.3%CVE-2026-74804CRITICALJoomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64EPSS 0.3%CVE-2026-77996HIGHJoomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41EPSS 0.2%CVE-2026-77028MEDIUMJoomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66EPSS 0.2%CVE-2026-77997MEDIUMJoomla Extension - yootheme.com - Authenticated, privileged information disclosure about site modules YOOtheme Pro 1.0.0-5.0.40EPSS 0.2%CVE-2026-77029MEDIUMJoomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66EPSS 0.2%CVE-2026-76610MEDIUMJoomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65EPSS 0.2%