SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76613

HIGH · CVSS 8.6 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

An authenticated SQL injection vulnerability exists in YOOtheme Pro versions 1.0.0 to 5.0.40, allowing contributor-level users to manipulate SQL queries and inject arbitrary content. This critical flaw could lead to unauthorized data access or modification, potentially compromising the integrity of the database. Organizations using affected versions of YOOtheme Pro should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-76613
Severity
HIGH
CVSS
8.6
EPSS
0.29%

Original NVD Description

Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.