CVE-2026-77029: Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
Published Aug 21, 2026
·Updated
Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
Affected Software
1 affected component
yootheme.com Zoo Extension<4.1.66
Event History
Aug 21, 2026
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue applies to yootheme.com Zoo Extension versions earlier than 4.1.66. The provided information does not identify specific Joomla versions or configuration conditions.
2
What must an attacker be able to do to exploit this?
An attacker would need to cause a user to submit a request that triggers a front-end state change. The supplied data does not specify required user privileges, authentication status, or the affected actions.
3
What version should be used to remediate the issue?
Upgrade the Zoo Extension to version 4.1.66 or later. No alternative mitigations are provided in the available data.