CVE-2026-77996: Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41
Published Aug 25, 2026
·Updated
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
Affected Software
1 affected component
YOOtheme YOOtheme Pro>=1.0.0<=5.0.41
Event History
Aug 25, 2026
CVE Published
via MITRE·11:52 AM
Data Sourced
via MITRE·11:52 AM
DescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
YOOtheme Pro versions 1.0.0 through 5.0.41 are identified as affected. The issue is in the location custom field.
2
What access does an attacker need?
Exploitation requires an authenticated user with privileged access. The vulnerability is a stored XSS vector caused by missing escaping of the location custom field.