Каталог CVE

Разработчик: yootheme.com

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 4

Разработчик: yootheme.com
Средняя CVSS 6.9

CVE-2026-76610

Разработчикyootheme.com

Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.

20.08.2026 Активна
Средняя CVSS 5.1

CVE-2026-75114

Разработчикyootheme.com

Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation.

19.08.2026 Активна
Критическая CVSS 9.3

CVE-2026-74804

Разработчикyootheme.com

Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.ty…

19.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-74803

Разработчикyootheme.com

Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

19.08.2026 Требует внимания