CVE-2026-75115: Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40
Published Aug 21, 2026
·Updated
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.
Affected Software
1 affected component
YOOtheme YOOtheme Pro>=2.3.0<=5.0.40
Event History
Aug 21, 2026
CVE Published
via MITRE·12:14 PM
Data Sourced
via MITRE·12:14 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires an authenticated, authorized user with privileged access. The issue is not described as exploitable by unauthenticated visitors.