VYPR

YOOtheme Pro

by Joomla

CVEs (3)

  • CVE-2026-76613HigAug 21, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.

  • CVE-2026-77996HigAug 25, 2026
    risk 0.49cvss —epss 0.00

    Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.

  • CVE-2026-77997MedAug 25, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules…