CVE-2026-75115
yootheme.com YOOtheme Pro extension for Joomla
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.
- CVSS
- 7
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.21