Vulnerability Bulletins

CVE-2026-77996

   
Affected software JOOMLA
 
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-77996