Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-74803: Joomla Zoo Extension Allows Unsecured File Uploads

CVE-2026-74803 · published 15 days ago
Summary

The Zoo extension for Joomla, a popular content management system, has a security issue that allows an attacker to upload any type of file without needing a password. This can be used to spread malware or execute malicious code on a website. To fix this, update the Zoo extension to version 4.1.64 or higher.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
yootheme.com zoo extension for joomla 1.0.0-4.1.63
Original advisory text
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
Severity
10.0 Critical
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published19 Aug 2026
Updated30 Aug 2026
First seen19 Aug 2026
Sources
CVE-2026-74803 · MITRE
Monitor software like this
Free during beta