SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77029

MEDIUM · CVSS 4.6 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Joomla Extension from yootheme.com is vulnerable due to missing CSRF tokens on front-end state changes in versions prior to 4.1.66, allowing attackers to perform unauthorized actions on behalf of users. This could lead to potential data manipulation or unauthorized access, impacting the integrity of user interactions. Web administrators and developers using this extension should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-77029
Severity
MEDIUM
CVSS
4.6
EPSS
0.16%

Original NVD Description

Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66