Description
Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
Published: 2026-08-21
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Front-end state manipulation via missing CSRF tokens
Action: Immediate Update
AI Analysis

Impact

The vulnerability resides in the Zoo extension for Joomla (yootheme.com) versions earlier than 4.1.66. Missing CSRF tokens on front‑end state‑changing requests allow an attacker to trigger actions such as publishing or deleting content by submitting crafted requests from a browser. Classified as CWE‑352, the flaw permits unauthorized modification of content integrity without requiring elevated privileges.

Affected Systems

The affected product is yootheme.com Zoo extension for Joomla. Only versions prior to 4.1.66 are affected; no other products or versions are listed.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate severity. No EPSS score is available, so exploitation likelihood is unclear. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed large‑scale attacks. The attack vector is client‑side web application; an attacker can perform the exploit by sending a crafted HTTP request from a browser to a front‑end endpoint that changes state.

Generated by OpenCVE AI on August 21, 2026 at 13:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Zoo extension to version 4.1.66 or later, which includes CSRF protection on state‑changing requests.
  • If an upgrade cannot be performed immediately, restrict access to state‑changing URLs by applying permission checks or a .htaccess rule that blocks direct POST requests from unknown origins.
  • Verify that all front‑end actions that modify content are protected by CSRF tokens; consult the extension’s documentation for CSRF implementation guidelines.

Generated by OpenCVE AI on August 21, 2026 at 13:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.yootheme.com/ cve-icon cve-icon
History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Yootheme.com
Yootheme.com zoo Extension For Joomla
Vendors & Products Yootheme.com
Yootheme.com zoo Extension For Joomla

Fri, 21 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
Title Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Yootheme.com Zoo Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-21T19:16:33.222Z

Reserved: 2026-08-20T08:36:08.428Z

Link: CVE-2026-77029

cve-icon Vulnrichment

Updated: 2026-08-21T14:32:41.676Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T12:16:34.097

Modified: 2026-08-26T16:36:16.990

Link: CVE-2026-77029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:15:42Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)