SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76610

MEDIUM · CVSS 6.9 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla Extension from yootheme.com is vulnerable to unauthorized tag modifications due to insufficient access control checks in the comment controller endpoint for versions prior to 4.1.65. This flaw allows unauthenticated users to alter tags, potentially leading to content manipulation and disruption of site integrity. Joomla administrators and web developers using this extension should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-76610
Severity
MEDIUM
CVSS
6.9
EPSS
0.16%

Original NVD Description

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.