CVE-2026-77028: Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
Published Aug 21, 2026
·Updated
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
Affected Software
1 affected component
yootheme.com Zoo<4.1.66
Event History
Aug 21, 2026
CVE Published
via MITRE·12:13 PM
Data Sourced
via MITRE·12:13 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
Deployments using yootheme.com Zoo versions earlier than 4.1.66 are affected.
2
What input is involved in exploitation?
The issue is associated with the submission redirect parameter, which can be used for reflected cross-site scripting and an open redirect.