Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

CVE-2026-77029HighPublished 21 August 2026

ZOO (com_zoo) 4.1.65 - Unauthenticated Stored XSS (CVSS 8.6), Unauthenticated Arbitrary Directory Listing (6.9), Reflected XSS and Open Redirect (5.3), and Missing Front-End CSRF Protection

YOOtheme ZOO (com_zoo) 4.1.65 is affected by a further set of front-end vulnerabilities, all fixed in ZOO 4.1.66 released on 21 August 2026. All four were published as CVEs by the Joomla CNA on 21 August 2026, each crediting Phil Taylor of mySites.guru as finder, each with an affected range of 1.0.0 to 4.1.65. This rule covers 4.1.65 only, because anything below that is already flagged by the more severe rules for the CVSS 10.0 unauthenticated file upload (CVE-2026-74803, fixed in 4.1.64) and the tag-management authorisation flaw (CVE-2026-76610, fixed in 4.1.65). 1) Unauthenticated stored cross-site scripting via user-controlled fields (CVE-2026-76612, CVSS 4.0 base 8.6 High, AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N). Input supplied in comments and in user-supplied field elements is not escaped on output, so an anonymous visitor can store script that then runs in the browser of anyone who views the affected page, administrators included. This is the most severe of the four and the one to plan around. 2) Unauthenticated arbitrary directory listing via the Gallery element (CVE-2026-76611, CVSS 4.0 base 6.9 Medium, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N). The Gallery element used in front-end submission forms lets an anonymous visitor walk and list directories outside the intended media path. YOOtheme describe the same fix in their changelog as a path traversal in Gallery element frontend submission. 3) Reflected cross-site scripting and open redirect via the submission redirect parameter (CVE-2026-77028, CVSS 4.0 base 5.3 Medium, AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N). The redirect target used after a front-end submission is neither validated nor escaped, so an attacker-supplied link both bounces the visitor to an arbitrary destination and reflects script into the page. The YOOtheme changelog describes this only as rejecting external redirects, which understates the cross-site scripting half. 4) Missing CSRF tokens on front-end state changes (CVE-2026-77029, CVSS 4.0 base 4.6 Medium, AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N). Front-end and administrator state-changing tasks, including submission deletion, accept requests carrying no CSRF token, so a logged-in user can be made to delete or alter content simply by visiting an attacker-controlled page. The same release also fixes, without listing them as security fixes, two items sitting on the same unauthenticated front-end submission upload path that produced the CVSS 10.0 RCE: the Download element was not enforcing its configured extension allow-list for uploaded files, and the upload MIME validation added in 4.1.64 did not work on Joomla versions earlier than 4.4. Sites running Joomla 3 or Joomla 4.0 to 4.3 should therefore treat 4.1.66 as the first release in which the upload hardening is genuinely in force. 4.1.66 further fixes JSON and CSV extension validation on administrator imports, adds TLS certificate and hostname verification to Twitter API requests, and moves Akismet API traffic to TLS. Update to ZOO 4.1.66 or later. Until you can, remove the Gallery and Download elements from any published front-end submission form, disable guest commenting, or restrict those forms so that guests cannot reach them.

Affected versions: ≥ 4.1.65 and < 4.1.66

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 25 August 2026.