Vulnerability Bulletins

CVE-2026-76612

   
Affected software JOOMLA
 
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-76612