SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76611

MEDIUM · CVSS 6.9 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla extension from yootheme.com is vulnerable to unauthenticated arbitrary directory listing through the Gallery element in versions prior to 4.1.66. This flaw could allow attackers to access sensitive directory contents without authentication, potentially exposing critical information. Joomla administrators and users of the affected extension should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-76611
Severity
MEDIUM
CVSS
6.9
EPSS
0.33%

Original NVD Description

Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.