CVE-2026-77997: Joomla Extension - yootheme.com - Authenticated, privileged information disclosure about site modules YOOtheme Pro 1.0.0-5.0.40
Published Aug 25, 2026
·Updated
Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with comtemplate editing permissions to access information about arbitrary modules without the respective commodules permissions.
Affected Software
1 affected component
YOOtheme YOOtheme Pro>=1.0.0<=5.0.41
Event History
Aug 25, 2026
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
DescriptionWeakness
Frequently Asked Questions
1
Which users can exploit this issue?
An authenticated user must have com_template editing permissions. They do not need the corresponding com_modules permissions to access information about arbitrary modules.
2
Which versions are affected?
The description identifies YOOtheme Pro versions 1.0.0 through 5.0.41 as affected.
3
What information can be exposed?
The issue allows access to information about arbitrary Joomla modules. The provided data does not identify the specific module fields or data types disclosed.