CVE-2026-76613 HIGH

CVE-2026-76613: Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40

Vendor Yootheme.com
Product YOOtheme Pro extension for Joomla
Weakness CWE-89 · SQLi
Published August 21, 2026
Last update August 23, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.

Explanation of Vulnerability in Simple Terms

02Summary

YOOtheme Pro for Joomla contains a SQL injection vulnerability in versions 1.0.0 through 5.0.40. An attacker with high-level privileges can inject malicious SQL commands to read, modify, or delete database content. This requires administrative or elevated account access to exploit.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete database records by injecting SQL commands through the extension.

Potential impact on your site

04Site Impact

A compromised admin account could allow an attacker to extract sensitive data, alter site content, or corrupt the Joomla database.

Conditions required to exploit

05Prerequisites

Attacker must have high-level Joomla administrator or privileged account access.

Key dates

06Disclosure timeline

August 21, 2026 CVE published
August 23, 2026 Record updated

Related vulnerabilities

08Related CVE