SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77996

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The YOOtheme Pro extension for Joomla versions 1.0.0 to 5.0.41 is vulnerable to an authenticated, privileged stored cross-site scripting (XSS) attack due to inadequate escaping in the location custom field. This flaw allows attackers with valid credentials to inject malicious scripts, potentially compromising user data and session integrity. Joomla administrators and web developers using this extension should prioritize applying security updates to mitigate the risk of exploitation.

CVE
CVE-2026-77996
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.