Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

YOOtheme Pro security vulnerabilities

mySites.guru tracks 2 vulnerabilities in YOOtheme Pro (location), covering 1 CVE. Every connected Joomla site is checked against them on each audit.

Is my site affected?

Your site is affected if it runs YOOtheme Pro in any of these ranges:

  • from 5.0.41 up to but not including 5.0.42
  • from 2.0.0 up to but not including 4.5.34
Latest safe version
5.0.42 or later. No rule we check matches that release or any newer one.
What to do
Update YOOtheme Pro to 5.0.42 or later from the vendor, then confirm the installed version on the Joomla administrator's Extensions: Manage screen.

Every YOOtheme Pro vulnerability we track

Newest first. CVSS is the score published in each CVE record, where it has one; the severity column is the rating our check uses.

CVEAffected versionsFixed inSeverityAdded
CVE-2026-77996CVSS 7.5from 5.0.41 up to but not including 5.0.425.0.42High2026-08-25
CVE-2026-77996CVSS 7.5from 2.0.0 up to but not including 4.5.344.5.34High2026-08-25

What we check for

HighCVE-2026-779962026-08-25

YOOtheme Pro (location) 5.0.41 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value (CVSS 7.5)

YOOtheme Pro 5.0.41's Location custom field (plg_fields_location) rendered its stored value straight into a hidden input's HTML attribute with no escaping, because LocationField::getInput() built that markup by plain string interpolation. A stored attribute-breakout payload therefore fires when the item's edit form is next opened by anyone, up to and including a Super User. Published as CVE-2026-77996 by the Joomla CNA on 25 August 2026, CVSS 4.0 base 7.5 High (AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N). The affected range on the record is 1.0.0 to 5.0.41. The CNA classes this as authenticated and privileged: storing the payload needs rights to edit an item that carries the field, and it only fires when someone later opens that item's edit form. As a Joomla custom field it can attach to articles, contacts, categories or users, so the practical exposure on any given site depends on which of those the field is attached to and who can edit them. Fixed in 5.0.42, which wraps the value in htmlspecialchars(..., ENT_QUOTES, 'UTF-8'). Confirmed by diffing the 5.0.41 and 5.0.42 packages. Note: this extension's technical identity (type=plugin, folder=fields, element=location) collides with two unrelated third-party extensions also named "Fields - Location", from developers Michael Richey and DigitAll Tools. Re-checked against live install data on 25 August 2026: they top out at 5.0.5 and 1.0 respectively, both below this rule's 5.0.41 floor, so neither is caught. Any future widening of this rule's floor must re-check that install base first. Update YOOtheme Pro to 5.0.42 or later through the Joomla Extensions manager, or download it from your YOOtheme account.

Affected versions: ≥ 5.0.41 and < 5.0.42

Full advisory: www.cve.org

HighCVE-2026-779962026-08-25

YOOtheme Pro (location) below 4.5.34 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value (CVSS 7.5)

The YOOtheme Location custom field plugin below 4.5.34, the Joomla 3 branch, writes the stored field value into a hidden input without escaping it, so a user who can set that field value can store JavaScript that then runs for anyone who later edits the item (CVE-2026-77996, CVSS 7.5). Fixed in 4.5.34 by escaping the value with htmlspecialchars(); update to 4.5.35, the current build on that branch. The Joomla 4/5/6 branch fixes the same flaw in 5.0.42. The version floor on this rule is deliberate: at least two unrelated vendors, Michael Richey and DigitAll Tools, also ship a plugin with folder "fields" and element "location", and their releases sit below 2.0.0 or above 5.0.0.

Affected versions: ≥ 2.0.0 and < 4.5.34

Full advisory: www.cve.org

Timeline

  1. 25 August 2026Check added for CVE-2026-77996 (from 5.0.41 up to but not including 5.0.42)
  2. 25 August 2026Check added for CVE-2026-77996 (from 2.0.0 up to but not including 4.5.34)
  3. 25 August 2026CVE-2026-77996 record published

References

Each CVE page above links its official cve.org record and its NVD entry.

YOOtheme Pro vulnerability questions

Which versions of YOOtheme Pro are vulnerable?
mySites.guru tracks 2 vulnerabilities in YOOtheme Pro (location). A site is affected if its installed version is in any of these ranges: from 5.0.41 up to but not including 5.0.42; from 2.0.0 up to but not including 4.5.34.
What is the latest safe version of YOOtheme Pro?
5.0.42. Every vulnerability tracked here is fixed by 5.0.42, and no rule we check matches that release or any later one.
How do I check which version of YOOtheme Pro my Joomla site runs?
The installed version is listed on the Joomla administrator's Extensions: Manage screen; search it for location. mySites.guru reads the installed version on every audit of a connected site and checks it against these rules.

Running YOOtheme Pro on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

CVE identifiers: CVE-2026-77996. Rules current as of 5 October 2026.