Description
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
Published: 2026-08-25
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Update Immediately
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw caused by missing escape handling in the custom location field of the YOOtheme Pro extension. An attacker who can supply input to this field can persist malicious JavaScript that will execute whenever a privileged user views the affected page. This type of flaw is classified under CWE‑79 and compromises the confidentiality and integrity of user sessions or can be used for defacement.

Affected Systems

The flaw exists in the YOOtheme Pro extension for Joomla, versions 1.0.0 through 5.0.41. Any website running the extension within that version range is potentially impacted.

Risk and Exploitability

With a CVSS score of 7.5 the issue is considered high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the impact is significant for any authenticated user who has write access to the custom location field. The attack requires legitimate authorized credentials to add or edit content, after which the stored payload will run in the browsers of other privileged users who view the page.

Generated by OpenCVE AI on August 25, 2026 at 13:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade YOOtheme Pro extension to the latest version that removes the unescaped input handling.
  • If an upgrade cannot be performed immediately, configure the extension or site to disable or remove the location custom field to prevent further injections, and enforce strict input validation on that field.
  • Audit existing content: review all pages and components that use the custom location field, remove any embedded malicious script, and purge or regenerate any cached content containing old payloads.

Generated by OpenCVE AI on August 25, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.yootheme.com/ cve-icon cve-icon
History

Tue, 25 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Yootheme.com
Yootheme.com yootheme Pro Extension For Joomla
Vendors & Products Yootheme.com
Yootheme.com yootheme Pro Extension For Joomla

Tue, 25 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
Title Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N'}


Subscriptions

Yootheme.com Yootheme Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-26T06:54:36.136Z

Reserved: 2026-08-21T19:23:55.924Z

Link: CVE-2026-77996

cve-icon Vulnrichment

Updated: 2026-08-25T12:52:46.421Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T12:16:25.973

Modified: 2026-08-26T16:36:16.990

Link: CVE-2026-77996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T14:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')