Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.yootheme.com/ |
|
History
Wed, 19 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping. | |
| Title | Joomla Extension - yootheme.com - Unauthenticated SQL injection in Zoo < 4.1.64 | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-08-19T13:35:50.248Z
Reserved: 2026-08-16T13:48:13.135Z
Link: CVE-2026-74804
No data.
Status : Received
Published: 2026-08-19T14:17:39.643
Modified: 2026-08-19T14:17:39.643
Link: CVE-2026-74804
No data.
OpenCVE Enrichment
No data.
Weaknesses