CVE-2026-76610: Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65
Published Aug 20, 2026
·Updated
Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.
Affected Software
1 affected component
Joomla Zoo<4.1.65
Event History
Aug 20, 2026
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated users can exploit the comment controller endpoint to make unauthorized tag modifications. No prior authentication is required.
2
Which deployments are affected?
Joomla sites using the Zoo extension are affected when Zoo is earlier than version 4.1.65. The provided information does not identify any configuration prerequisite.
3
What is the remediation?
Update Zoo to version 4.1.65 or later. This version boundary indicates that releases before 4.1.65 are affected.