Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.yootheme.com/ |
|
History
Wed, 19 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group. | |
| Title | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-08-19T15:02:47.974Z
Reserved: 2026-08-16T13:48:13.135Z
Link: CVE-2026-74803
No data.
Status : Received
Published: 2026-08-19T14:17:39.487
Modified: 2026-08-19T14:17:39.487
Link: CVE-2026-74803
No data.
OpenCVE Enrichment
Updated: 2026-08-19T18:30:03Z
Weaknesses