Junglewise Threat Intelligence

CVE-2026-77028: YOOtheme Zoo reflected XSS and open redirect in submission redirect parameter

CVE-2026-77028 · Severity: info · Published 2026-08-21

Technologies: YOOtheme Zoo. Vendors: YOOtheme.

Executive brief

YOOtheme Zoo is a content management extension for Joomla used to organize and display structured content. This vulnerability allows attackers to inject malicious scripts into web pages viewed by users (reflected XSS) or redirect users to attacker-controlled websites through improper handling of the submission redirect parameter, potentially leading to credential theft or phishing attacks.

Technical details

The vulnerability is a combined reflected cross-site scripting (XSS) and open redirect flaw in YOOtheme Zoo versions prior to 4.1.66. The vulnerable component is the submission redirect parameter, which fails to properly validate or sanitize user input before reflecting it back in HTTP responses or using it for redirects. An attacker can craft a malicious URL containing JavaScript payload or a redirect target and trick users into clicking it. Exploitation does not require authentication or special privileges. The impact includes session hijacking through reflected XSS and user redirection to phishing or malware sites via the open redirect.

Affected products

  • YOOtheme Zoo < 4.1.66

Timeline

  • 2026-08-21: disclosed

References

Related threats