CVE-2026-76612: Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66
Published Aug 21, 2026
·Updated
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.
Affected Software
1 affected component
Joomla Extension - yootheme.com<4.1.66
Event History
Aug 21, 2026
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Zoo versions earlier than 4.1.66 are affected where comments or user-supplied field elements can accept attacker-controlled input. The issue is in the Joomla extension from yootheme.com.
2
What does an attacker need to exploit it?
An attacker needs a way to submit input through comments or user-supplied field elements. Authentication is not required.
3
What should be done to remediate the issue?
Upgrade Zoo to version 4.1.66 or later. If upgrading cannot happen immediately, restrict or disable untrusted comment and user-supplied field submissions where possible.