CVE-2026-76613: Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40
Published Aug 21, 2026
·Updated
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.
Affected Software
1 affected component
YOOtheme YOOtheme Pro>=1.0.0<=5.0.40
Event History
Aug 21, 2026
CVE Published
via MITRE·12:14 PM
Data Sourced
via MITRE·12:14 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated contributor-level user can exploit it. The available information does not indicate that unauthenticated users can trigger the flaw.
2
Which releases are affected?
YOOtheme Pro versions 1.0.0 through 5.0.40 are identified as affected.
3
What access does an attacker need to abuse the vulnerability?
The attacker needs a contributor-level account and must be able to submit content that is incorporated into SQL queries.