Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-74803CriticalCVSS 10.0CVE published 19 August 2026Added to mySites.guru 19 August 2026

ZOO (com_zoo) below 4.1.64 - Unauthenticated Arbitrary File Upload (RCE, CVSS 10.0), Unauthenticated SQL Injection (CVSS 9.3) and Open Redirect

YOOtheme ZOO (com_zoo) up to and including 4.1.63 contains three unauthenticated vulnerabilities, all fixed in 4.1.64 released on 19 August 2026, and all published as CVEs by the Joomla CNA on 19 August 2026. All three were found and reported by Phil Taylor of mySites.guru, who is credited as finder on each record. Every one was proved live on a test install, not inferred from reading code. 1) Unauthenticated arbitrary file upload leading to remote code execution (CVE-2026-74803, CWE-434, CVSS 4.0 base 10.0 Critical, AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). The Image element used in ZOO front-end submission forms validates uploads against the client-supplied Content-Type header only. It never inspects the file contents and sets no extension allow-list, and the filename passes through Joomla File::makeSafe, which preserves a .php extension. An anonymous visitor can therefore submit a PHP file declared as image/jpeg and have it written into images/zoo/uploads/ inside the web root, where the web server executes it. That is a full remote code execution with no login, no CSRF obstacle and no user interaction. Guest access to submissions is the ZOO default and captcha is off by default. A proof-of-concept shell uploaded this way executed on the test host. 2) Unauthenticated SQL injection (CVE-2026-74804, CWE-89, CVSS 4.0 base 9.3 Critical). ItemController::element() interpolates the filter_type request value straight into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting and no escaping. An anonymous request to index.php?option=com_zoo&app_id=<id>&controller=item&task=element can break out of the string, bypass the published-state and view-access filters to read unpublished and access-restricted items, and use a UNION to read arbitrary data from the database. Exfiltration of the MySQL version and the database name was demonstrated as an unauthenticated guest. 3) Open redirect (CVE-2026-75114, CWE-601, CVSS 4.0 base 5.1 Medium). CommentController::twitterAuthenticate() passes the referer request parameter directly to setRedirect() with no scheme or host validation, so the site issues an HTTP 303 to any attacker-chosen destination. It works whether or not Twitter authentication is configured, and gives phishing campaigns a redirect through a trusted domain. Update to ZOO 4.1.66 or later now - 4.1.64 fixed these three findings, but 4.1.65 and 4.1.66 each fixed further ones, so 4.1.66 is the minimum safe version. Until you can: remove the Image element from any published front-end submission form, or restrict those forms so guests cannot reach them, and audit images/zoo/uploads/ for anything that is not an image. Because the upload flaw needs no login, any site that ran a vulnerable version while internet-facing should be treated as potentially compromised until checked - look for .php files anywhere under images/, for administrator accounts you do not recognise, and consider rotating the Joomla secret and stored credentials. Two further releases followed. 4.1.65 completed the tag-management authorisation fix, published as CVE-2026-76610 (CVSS 6.9). 4.1.66, on 21 August 2026, fixed three more published CVEs on the front-end submission path (CVE-2026-76611 arbitrary directory listing, CVE-2026-77028 reflected XSS and open redirect, CVE-2026-77029 missing CSRF protection) plus two unannounced hardening fixes on the same upload path that produced the RCE. All of these are also credited to Phil Taylor of mySites.guru. The minimum safe version is 4.1.66.

Is my site affected?

Affected
ZOO before 4.1.64
Fixed in
4.1.64
What to do
Update ZOO to 4.1.64 for this flaw, or to 4.1.66 or later, which no rule we check matches.

How CVE-2026-74803 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

10.0 Critical

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:H Confidentiality
High. Everything the site holds can be read
VI:H Integrity
High. Data and files can be altered at will
VA:H Availability
High. The site can be taken down

What it does beyond the site

SC:H Confidentiality
High. Data on other systems can be read
SI:H Integrity
High. Other systems can be altered
SA:H Availability
High. Other systems can be taken down

Timeline

  1. 19 August 2026CVE-2026-74803 record published by its CNA
  2. 19 August 2026mySites.guru check added for ZOO (before 4.1.64)

Rule details

Other vulnerabilities in ZOO

Updating for CVE-2026-74803 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

ZOO

Latest safe version: 4.1.66

References

CVE-2026-74803 questions

Which versions are affected by CVE-2026-74803?
CVE-2026-74803 affects ZOO before 4.1.64. The fix is in 4.1.64.
How do I fix CVE-2026-74803?
Update ZOO to 4.1.64 for this flaw, or to 4.1.66 or later, which no rule we check matches. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2026-74803?
Joomla CNA scores it 10.0 (Critical) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.