CyberRota Analysis
AI-GeneratedThe Joomla Extension from yootheme.com is vulnerable to reflected cross-site scripting (XSS) and open redirect attacks through the submission redirect parameter in versions prior to 4.1.66. This vulnerability could allow attackers to execute malicious scripts in the context of a user's session, potentially compromising user data and session integrity. Web administrators using affected versions of the Zoo extension should prioritize applying the latest updates to mitigate these risks.
CVE
CVE-2026-77028
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%
Original NVD Description
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66