Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-77996HighCVSS 7.5CVE published 25 August 2026Added to mySites.guru 25 August 2026

YOOtheme Pro (location) 5.0.41 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value

YOOtheme Pro 5.0.41's Location custom field (plg_fields_location) rendered its stored value straight into a hidden input's HTML attribute with no escaping, because LocationField::getInput() built that markup by plain string interpolation. A stored attribute-breakout payload therefore fires when the item's edit form is next opened by anyone, up to and including a Super User. Published as CVE-2026-77996 by the Joomla CNA on 25 August 2026, CVSS 4.0 base 7.5 High (AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N). The affected range on the record is 1.0.0 to 5.0.41. The CNA classes this as authenticated and privileged: storing the payload needs rights to edit an item that carries the field, and it only fires when someone later opens that item's edit form. As a Joomla custom field it can attach to articles, contacts, categories or users, so the practical exposure on any given site depends on which of those the field is attached to and who can edit them. Fixed in 5.0.42, which wraps the value in htmlspecialchars(..., ENT_QUOTES, 'UTF-8'). Confirmed by diffing the 5.0.41 and 5.0.42 packages. Note: this extension's technical identity (type=plugin, folder=fields, element=location) collides with two unrelated third-party extensions also named "Fields - Location", from developers Michael Richey and DigitAll Tools. Re-checked against live install data on 25 August 2026: they top out at 5.0.5 and 1.0 respectively, both below this rule's 5.0.41 floor, so neither is caught. Any future widening of this rule's floor must re-check that install base first. Update YOOtheme Pro to 5.0.42 or later through the Joomla Extensions manager, or download it from your YOOtheme account.

Is my site affected?

CVE-2026-77996 is checked by 2 rules. Find the extension and release line your site runs:

ExtensionAffected versionsFixed inWhat to do
YOOtheme Profrom 5.0.41 up to but not including 5.0.425.0.42Update YOOtheme Pro to 5.0.42 or later.
YOOtheme Profrom 2.0.0 up to but not including 4.5.344.5.34Update YOOtheme Pro to 4.5.34 or later.

How CVE-2026-77996 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

7.5 High

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:P Attack requirements
Present. Needs a particular deployment or race to line up
PR:H Privileges required
High. Needs an account with elevated rights
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:H Confidentiality
High. Everything the site holds can be read
VI:H Integrity
High. Data and files can be altered at will
VA:L Availability
Low. The site slows or stutters

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

Timeline

  1. 25 August 2026CVE-2026-77996 record published by its CNA
  2. 25 August 2026mySites.guru check added for YOOtheme Pro (from 5.0.41 up to but not including 5.0.42)
  3. 25 August 2026mySites.guru check added for YOOtheme Pro (from 2.0.0 up to but not including 4.5.34)

Rule details

HighCVE-2026-779962026-08-25

YOOtheme Pro - YOOtheme Pro (location) below 4.5.34 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value (CVSS 7.5)

The YOOtheme Location custom field plugin below 4.5.34, the Joomla 3 branch, writes the stored field value into a hidden input without escaping it, so a user who can set that field value can store JavaScript that then runs for anyone who later edits the item (CVE-2026-77996, CVSS 7.5). Fixed in 4.5.34 by escaping the value with htmlspecialchars(); update to 4.5.35, the current build on that branch. The Joomla 4/5/6 branch fixes the same flaw in 5.0.42. The version floor on this rule is deliberate: at least two unrelated vendors, Michael Richey and DigitAll Tools, also ship a plugin with folder "fields" and element "location", and their releases sit below 2.0.0 or above 5.0.0.

Affected versions: ≥ 2.0.0 and < 4.5.34

Full advisory: www.cve.org

Other vulnerabilities in YOOtheme Pro

Updating for CVE-2026-77996 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

YOOtheme Pro

Latest safe version: 5.0.42

References

CVE-2026-77996 questions

Which versions are affected by CVE-2026-77996?
CVE-2026-77996 is covered by 2 rules: YOOtheme Pro from 5.0.41 up to but not including 5.0.42; YOOtheme Pro from 2.0.0 up to but not including 4.5.34.
How do I fix CVE-2026-77996?
It depends on the extension and release line your site runs. For YOOtheme Pro from 5.0.41 up to but not including 5.0.42: update YOOtheme Pro to 5.0.42 or later. For YOOtheme Pro from 2.0.0 up to but not including 4.5.34: update YOOtheme Pro to 4.5.34 or later.
How severe is CVE-2026-77996?
Joomla CNA scores it 7.5 (High) under CVSS 4.0. In plain terms: reachable across the internet, needs an account with elevated rights and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.