Affected versions: < 4.5.34
Full advisory: www.cve.org
Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE
YOOtheme Pro below 4.5.34, the Joomla 3 branch, has three flaws reachable by an authenticated user who can edit templates. CVE-2026-76613 (CVSS 8.6) is an SQL injection in the page builder's article and tag source ORDER BY handling. CVE-2026-75115 (CVSS 7.0) is an arbitrary file read via a glob-pattern escape in the Filesystem source path filter. CVE-2026-77997 (CVSS 5.1) is a missing authorisation check in the module controller that returns any module's configuration to a user who holds only com_templates edit rights. All three are fixed in 4.5.34, released 24 August 2026. Update to 4.5.35, released 25 August 2026, which adds a regression fix for custom-field ordering in the Articles model. Sites on 1.x, 2.x, 3.x or 4.0 to 4.4 have no fixed release on their own line: the fix is to move to 4.5.35, or to migrate to the 5.0.x branch on Joomla 4/5/6. All three CVEs are scored PR:H, so an attacker needs an existing privileged account rather than anonymous access.
Affected versions: < 4.5.34
Official record: cve.org · NVD
Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.
Affected versions: < 4.5.34
Full advisory: www.cve.org
YOOtheme Pro - YOOtheme Pro (yootheme) below 4.5.34 - Authenticated SQL Injection (CVSS 8.6), Arbitrary File Read (CVSS 7.0) and Broken Access Control (CVSS 5.1)
YOOtheme Pro below 4.5.34, the Joomla 3 branch, has three flaws reachable by an authenticated user who can edit templates. CVE-2026-76613 (CVSS 8.6) is an SQL injection in the page builder's article and tag source ORDER BY handling. CVE-2026-75115 (CVSS 7.0) is an arbitrary file read via a glob-pattern escape in the Filesystem source path filter. CVE-2026-77997 (CVSS 5.1) is a missing authorisation check in the module controller that returns any module's configuration to a user who holds only com_templates edit rights. All three are fixed in 4.5.34, released 24 August 2026. Update to 4.5.35, released 25 August 2026, which adds a regression fix for custom-field ordering in the Articles model. Sites on 1.x, 2.x, 3.x or 4.0 to 4.4 have no fixed release on their own line: the fix is to move to 4.5.35, or to migrate to the 5.0.x branch on Joomla 4/5/6. All three CVEs are scored PR:H, so an attacker needs an existing privileged account rather than anonymous access.
Affected versions: < 4.5.34
Full advisory: www.cve.org
YOOtheme Pro - YOOtheme Pro (yootheme) 5.0.0 to 5.0.40 - Authenticated SQL Injection (CVSS 8.6) and Arbitrary File Read (CVSS 7.0)
YOOtheme Pro 5.0.0 to 5.0.40, the Joomla 4/5/6 branch, has two flaws reachable by an authenticated user who can edit templates. CVE-2026-76613 (CVSS 8.6) is an SQL injection: the page builder's article and tag source queries put the ORDER BY column straight into the query without quoting it. CVE-2026-75115 (CVSS 7.0) is an arbitrary file read: the Filesystem source path filter can be stepped outside its root directories with glob patterns. Both are fixed in 5.0.41. Update to 5.0.42, which also fixes CVE-2026-77996 and CVE-2026-77997. YOOtheme keeps a separate Joomla 3 branch that fixes the same flaws in 4.5.34, so a site reporting 4.5.34 or later is patched and is covered by the matching 4.5.x advisory instead. Both CVEs are scored PR:H, so an attacker needs an existing privileged account rather than anonymous access.
Affected versions: ≥ 5.0.0 and < 5.0.41
Full advisory: www.cve.org
YOOtheme Pro - YOOtheme Pro (yootheme) 5.0.0 to 5.0.40 - Authenticated SQL Injection (CVSS 8.6) and Arbitrary File Read (CVSS 7.0)
YOOtheme Pro 5.0.0 to 5.0.40, the Joomla 4/5/6 branch, has two flaws reachable by an authenticated user who can edit templates. CVE-2026-76613 (CVSS 8.6) is an SQL injection: the page builder's article and tag source queries put the ORDER BY column straight into the query without quoting it. CVE-2026-75115 (CVSS 7.0) is an arbitrary file read: the Filesystem source path filter can be stepped outside its root directories with glob patterns. Both are fixed in 5.0.41. Update to 5.0.42, which also fixes CVE-2026-77996 and CVE-2026-77997. YOOtheme keeps a separate Joomla 3 branch that fixes the same flaws in 4.5.34, so a site reporting 4.5.34 or later is patched and is covered by the matching 4.5.x advisory instead. Both CVEs are scored PR:H, so an attacker needs an existing privileged account rather than anonymous access.
Affected versions: ≥ 5.0.0 and < 5.0.41
Full advisory: www.cve.org
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 25 August 2026.