Junglewise Threat Intelligence

CVE-2026-77029: YOOtheme Zoo CSRF vulnerability in front-end state changes

CVE-2026-77029 · Severity: info · Published 2026-08-21

Technologies: YOOtheme Zoo. Vendors: YOOtheme.

Executive brief

YOOtheme Zoo is a popular Joomla extension that provides content management and display capabilities for Joomla websites. The extension fails to implement CSRF (Cross-Site Request Forgery) protections on front-end state-changing operations, allowing attackers to trick users into performing unintended actions such as modifying content or settings without their knowledge.

Technical details

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in YOOtheme Zoo versions before 4.1.66, where front-end state-changing operations lack proper CSRF token validation. An attacker can craft a malicious webpage or email that, when visited by an authenticated Zoo user, silently executes state-changing actions without the user's explicit consent. The attack vector is network-based and requires no special privileges, though it does require the user to be authenticated and visit an attacker-controlled page while logged in. Affected versions prior to 4.1.66 are vulnerable; users should upgrade to 4.1.66 or later to remediate.

Affected products

  • YOOtheme Zoo < 4.1.66

Timeline

  • 2026-08-21: disclosed

References

Related threats