Description
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.
Published: 2026-08-21
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Zoo extension for Joomla versions earlier than 4.1.66 where user supplied input in comments and custom field elements is not escaped before rendering, allowing an attacker to embed arbitrary script code. This stored cross‑site scripting flaw is classified as CWE‑79. If triggered, malicious code would run in the browser context of any visitor to a page displaying the affected content, potentially leading to credential theft, session hijacking, or defacement, while not modifying the underlying database directly.

Affected Systems

Systems using the yootheme.com Zoo extension for Joomla that are running a version earlier than 4.1.66 are affected. This includes any Joomla site that has incorporated Zoo before the indicated release, regardless of whether the site is publicly exposed or restricted to internal users.

Risk and Exploitability

The flaw carries a CVSS v3.1 score of 8.6, indicating high severity. No EPSS score is provided, and the vulnerability is currently not listed in CISA's KEV catalog, suggesting it has not yet been actively exploited at scale. Attackers can trigger the issue without authentication by submitting malicious scripts via the comment form or by creating entries with injected scripts in user‑supplied field elements, thereby achieving a stored XSS vector that will execute on any subsequent page view.

Generated by OpenCVE AI on August 21, 2026 at 13:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Zoo extension version 4.1.66 or later, which includes input‑escaping for comments and custom fields.
  • Ensure any existing comments or custom fields containing injected scripts are sanitized or removed after the upgrade.
  • Inspect other extensions or themes that render user input for similar lack of output escaping and apply updates or patches.

Generated by OpenCVE AI on August 21, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.yootheme.com/ cve-icon cve-icon
History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Yootheme.com
Yootheme.com zoo Extension For Joomla
Vendors & Products Yootheme.com
Yootheme.com zoo Extension For Joomla

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.
Title Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Yootheme.com Zoo Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-21T19:22:11.591Z

Reserved: 2026-08-19T14:48:01.169Z

Link: CVE-2026-76612

cve-icon Vulnrichment

Updated: 2026-08-21T16:11:20.600Z

cve-icon NVD

Status : Received

Published: 2026-08-21T13:18:19.990

Modified: 2026-08-21T16:18:18.870

Link: CVE-2026-76612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:15:34Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')