CVE-2026-74803 CRITICAL

CVE-2026-74803: Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64

Vendor Yootheme.com
Product Zoo extension for Joomla
Weakness CWE-434 · Unrestricted file upload
Published August 19, 2026
Last update August 21, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

Explanation of Vulnerability in Simple Terms

02Summary

The Zoo extension for Joomla contains an unrestricted file upload vulnerability that allows attackers to upload files with dangerous types without authentication. An attacker can upload malicious files (such as PHP scripts) directly to the server, leading to remote code execution. This affects Zoo versions 1.0.0-4.1.63 and earlier. Sites running this extension are at critical risk.

What an attacker can do

03Attacker Capabilities

Upload and execute malicious files on the server, gaining full control of the Joomla site.

Potential impact on your site

04Site Impact

Complete compromise of the Joomla installation; attacker can read/modify/delete all data and user accounts.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 19, 2026 CVE published
August 21, 2026 Record updated

Related vulnerabilities

08Related CVE