Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-76611MediumCVSS 6.9CVE published 21 August 2026Added to mySites.guru 21 August 2026

ZOO (com_zoo) 4.1.65 - Unauthenticated Stored XSS (CVSS 8.6), Unauthenticated Arbitrary Directory Listing (6.9), Reflected XSS and Open Redirect (5.3), and Missing Front-End CSRF Protection

YOOtheme ZOO (com_zoo) 4.1.65 is affected by a further set of front-end vulnerabilities, all fixed in ZOO 4.1.66 released on 21 August 2026. All four were published as CVEs by the Joomla CNA on 21 August 2026, each crediting Phil Taylor of mySites.guru as finder, each with an affected range of 1.0.0 to 4.1.65. This rule covers 4.1.65 only, because anything below that is already flagged by the more severe rules for the CVSS 10.0 unauthenticated file upload (CVE-2026-74803, fixed in 4.1.64) and the tag-management authorisation flaw (CVE-2026-76610, fixed in 4.1.65). 1) Unauthenticated stored cross-site scripting via user-controlled fields (CVE-2026-76612, CVSS 4.0 base 8.6 High, AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N). Input supplied in comments and in user-supplied field elements is not escaped on output, so an anonymous visitor can store script that then runs in the browser of anyone who views the affected page, administrators included. This is the most severe of the four and the one to plan around. 2) Unauthenticated arbitrary directory listing via the Gallery element (CVE-2026-76611, CVSS 4.0 base 6.9 Medium, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N). The Gallery element used in front-end submission forms lets an anonymous visitor walk and list directories outside the intended media path. YOOtheme describe the same fix in their changelog as a path traversal in Gallery element frontend submission. 3) Reflected cross-site scripting and open redirect via the submission redirect parameter (CVE-2026-77028, CVSS 4.0 base 5.3 Medium, AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N). The redirect target used after a front-end submission is neither validated nor escaped, so an attacker-supplied link both bounces the visitor to an arbitrary destination and reflects script into the page. The YOOtheme changelog describes this only as rejecting external redirects, which understates the cross-site scripting half. 4) Missing CSRF tokens on front-end state changes (CVE-2026-77029, CVSS 4.0 base 4.6 Medium, AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N). Front-end and administrator state-changing tasks, including submission deletion, accept requests carrying no CSRF token, so a logged-in user can be made to delete or alter content simply by visiting an attacker-controlled page. The same release also fixes, without listing them as security fixes, two items sitting on the same unauthenticated front-end submission upload path that produced the CVSS 10.0 RCE: the Download element was not enforcing its configured extension allow-list for uploaded files, and the upload MIME validation added in 4.1.64 did not work on Joomla versions earlier than 4.4. Sites running Joomla 3 or Joomla 4.0 to 4.3 should therefore treat 4.1.66 as the first release in which the upload hardening is genuinely in force. 4.1.66 further fixes JSON and CSV extension validation on administrator imports, adds TLS certificate and hostname verification to Twitter API requests, and moves Akismet API traffic to TLS. Update to ZOO 4.1.66 or later. Until you can, remove the Gallery and Download elements from any published front-end submission form, disable guest commenting, or restrict those forms so that guests cannot reach them.

Is my site affected?

Affected
ZOO from 4.1.65 up to but not including 4.1.66
Fixed in
4.1.66
What to do
Update ZOO to 4.1.66 or later.

How CVE-2026-76611 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

6.9 Medium

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:N Confidentiality
None. Nothing can be read
VI:L Integrity
Low. Some data can be altered
VA:N Availability
None. The site stays up

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

The rule below is rated High for the set of 4 CVEs it covers together, not for this record on its own.

Timeline

  1. 21 August 2026CVE-2026-76611 record published by its CNA
  2. 21 August 2026mySites.guru check added for ZOO (from 4.1.65 up to but not including 4.1.66)

Rule details

Other vulnerabilities in ZOO

Updating for CVE-2026-76611 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

ZOO

Latest safe version: 4.1.66

References

CVE-2026-76611 questions

Which versions are affected by CVE-2026-76611?
CVE-2026-76611 affects ZOO from 4.1.65 up to but not including 4.1.66. The fix is in 4.1.66.
How do I fix CVE-2026-76611?
Update ZOO to 4.1.66 or later. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2026-76611?
Joomla CNA scores it 6.9 (Medium) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.