Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.yootheme.com/ |
|
Fri, 21 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yootheme.com
Yootheme.com zoo Extension For Joomla |
|
| Vendors & Products |
Yootheme.com
Yootheme.com zoo Extension For Joomla |
Thu, 20 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation. | |
| Title | Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-08-21T04:47:56.526Z
Reserved: 2026-08-17T17:51:11.409Z
Link: CVE-2026-75114
Updated: 2026-08-20T15:53:20.276Z
Status : Received
Published: 2026-08-19T14:17:40.353
Modified: 2026-08-20T16:18:01.593
Link: CVE-2026-75114
No data.
OpenCVE Enrichment
Updated: 2026-08-21T21:16:33Z