Affected versions: < 4.5.34
Full advisory: www.cve.org
YOOtheme Pro below 4.5.34, the Joomla 3 branch, has three flaws reachable by an authenticated user who can edit templates. CVE-2026-76613 (CVSS 8.6) is an SQL injection in the page builder's article and tag source ORDER BY handling. CVE-2026-75115 (CVSS 7.0) is an arbitrary file read via a glob-pattern escape in the Filesystem source path filter. CVE-2026-77997 (CVSS 5.1) is a missing authorisation check in the module controller that returns any module's configuration to a user who holds only com_templates edit rights. All three are fixed in 4.5.34, released 24 August 2026. Update to 4.5.35, released 25 August 2026, which adds a regression fix for custom-field ordering in the Articles model. Sites on 1.x, 2.x, 3.x or 4.0 to 4.4 have no fixed release on their own line: the fix is to move to 4.5.35, or to migrate to the 5.0.x branch on Joomla 4/5/6. All three CVEs are scored PR:H, so an attacker needs an existing privileged account rather than anonymous access.
CVE-2026-76613 is checked by 2 rules. Find the extension and release line your site runs:
| Extension | Affected versions | Fixed in | What to do |
|---|---|---|---|
| YOOtheme Pro | before 4.5.34 | 4.5.34 | Update YOOtheme Pro to 4.5.34 or later. |
| YOOtheme Pro | from 5.0.0 up to but not including 5.0.41 | 5.0.41 | Update YOOtheme Pro to 5.0.41 for this flaw, or to 5.0.42 or later, which no rule we check matches. |
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
8.6 High
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NAffected versions: < 4.5.34
Full advisory: www.cve.org
YOOtheme Pro - YOOtheme Pro (yootheme) 5.0.0 to 5.0.40 - Authenticated SQL Injection (CVSS 8.6) and Arbitrary File Read (CVSS 7.0)
YOOtheme Pro 5.0.0 to 5.0.40, the Joomla 4/5/6 branch, has two flaws reachable by an authenticated user who can edit templates. CVE-2026-76613 (CVSS 8.6) is an SQL injection: the page builder's article and tag source queries put the ORDER BY column straight into the query without quoting it. CVE-2026-75115 (CVSS 7.0) is an arbitrary file read: the Filesystem source path filter can be stepped outside its root directories with glob patterns. Both are fixed in 5.0.41. Update to 5.0.42, which also fixes CVE-2026-77996 and CVE-2026-77997. YOOtheme keeps a separate Joomla 3 branch that fixes the same flaws in 4.5.34, so a site reporting 4.5.34 or later is patched and is covered by the matching 4.5.x advisory instead. Both CVEs are scored PR:H, so an attacker needs an existing privileged account rather than anonymous access.
Affected versions: ≥ 5.0.0 and < 5.0.41
Full advisory: www.cve.org
Updating for CVE-2026-76613 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
Latest safe version: 5.0.42
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.
Rules current as of 5 October 2026.