Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

CVE-2026-77996HighPublished 25 August 2026

YOOtheme Pro (location) 5.0.41 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value

YOOtheme Pro 5.0.41's Location custom field (plg_fields_location) rendered its stored value straight into a hidden input's HTML attribute with no escaping, because LocationField::getInput() built that markup by plain string interpolation. A stored attribute-breakout payload therefore fires when the item's edit form is next opened by anyone, up to and including a Super User. Published as CVE-2026-77996 by the Joomla CNA on 25 August 2026, CVSS 4.0 base 7.5 High (AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N). The affected range on the record is 1.0.0 to 5.0.41. The CNA classes this as authenticated and privileged: storing the payload needs rights to edit an item that carries the field, and it only fires when someone later opens that item's edit form. As a Joomla custom field it can attach to articles, contacts, categories or users, so the practical exposure on any given site depends on which of those the field is attached to and who can edit them. Fixed in 5.0.42, which wraps the value in htmlspecialchars(..., ENT_QUOTES, 'UTF-8'). Confirmed by diffing the 5.0.41 and 5.0.42 packages. Note: this extension's technical identity (type=plugin, folder=fields, element=location) collides with two unrelated third-party extensions also named "Fields - Location", from developers Michael Richey and DigitAll Tools. Re-checked against live install data on 25 August 2026: they top out at 5.0.5 and 1.0 respectively, both below this rule's 5.0.41 floor, so neither is caught. Any future widening of this rule's floor must re-check that install base first. Update YOOtheme Pro to 5.0.42 or later through the Joomla Extensions manager, or download it from your YOOtheme account.

Affected versions: ≥ 5.0.41 and < 5.0.42

Official record: cve.org · NVD

Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.

Affected extensions and versions

HighCVE-2026-779962026-08-25

YOOtheme Pro - YOOtheme Pro (location) below 4.5.34 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value (CVSS 7.5)

The YOOtheme Location custom field plugin below 4.5.34, the Joomla 3 branch, writes the stored field value into a hidden input without escaping it, so a user who can set that field value can store JavaScript that then runs for anyone who later edits the item (CVE-2026-77996, CVSS 7.5). Fixed in 4.5.34 by escaping the value with htmlspecialchars(); update to 4.5.35, the current build on that branch. The Joomla 4/5/6 branch fixes the same flaw in 5.0.42. The version floor on this rule is deliberate: at least two unrelated vendors, Michael Richey and DigitAll Tools, also ship a plugin with folder "fields" and element "location", and their releases sit below 2.0.0 or above 5.0.0.

Affected versions: ≥ 2.0.0 and < 4.5.34

Full advisory: www.cve.org

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 25 August 2026.