What is CVE-2026-74803?
CVE-2026-74803 is an unauthenticated arbitrary file upload vulnerability in the YOOtheme Zoo extension for Joomla (versions before 4.1.64). The image element accepts any file when the client-supplied Content-Type falls within the image MIME group. Zoo users must update to the latest version immediately.
Azərbaycanca: CVE-2026-74803, YOOtheme Zoo Joomla komponentində (4.1.64-dən əvvəlki versiyalar) autentifikasiya olmadan ixtiyari fayl yükləmə zəifliyidir. Image elementi, müştərinin təqdim etdiyi Content-Type şəkil MIME qrupunda olduqda istənilən faylı qəbul edir. Zoo istifadəçiləri dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
What component is affected by CVE-2026-74803 and what is the main threat?
CVE-2026-74803 is an unauthenticated arbitrary file upload vulnerability found in the YOOtheme Zoo extension for Joomla. The image element accepts any file when the client-supplied Content-Type falls within the image MIME group.
What action should be taken to protect against CVE-2026-74803?
Zoo users must update to the latest version immediately. The vulnerability affects versions before 4.1.64.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.