CVE-2026-76612EPSS p35.7%
CVE-2026-76612CVE-2026-76612
Description
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.
Scoring
| EPSS | 0.44% probability of exploitation · percentile 35.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-26 |