CVE-2026-76611: Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66
Published Aug 21, 2026
·Updated
Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.
Affected Software
1 affected component
Joomla Extension (yootheme.com) - Zoo Gallery element<4.1.66
Event History
Aug 21, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need to log in to exploit it.
2
Which deployments are affected?
Zoo Gallery element versions earlier than 4.1.66 are affected. The provided information does not identify any configuration prerequisite.
3
What information could an attacker obtain?
The vulnerability allows arbitrary directory listing, which can expose directory contents accessible to the affected component.