Executive brief
YOOtheme Zoo is a content management component for Joomla websites. The Gallery element in Zoo versions before 4.1.66 allows unauthenticated attackers to list arbitrary directories on the server, potentially exposing sensitive file paths and structure that could aid further attacks.
Technical details
An unauthenticated arbitrary directory listing vulnerability exists in the Gallery element of YOOtheme Zoo prior to version 4.1.66. The vulnerability allows attackers to enumerate and list files and directories on the web server without authentication. The attack vector is network-based and requires no special privileges or user interaction. While directory listing itself may seem informational, it can expose sensitive paths and enable reconnaissance for follow-up attacks. The vulnerability has been patched in Zoo 4.1.66 and later versions.
Affected products
- YOOtheme Zoo before 4.1.66
Timeline
- 2026-08-21: disclosed