What is CVE-2026-74804?
This vulnerability is an unauthenticated SQL injection in the YooTheme Zoo Joomla extension prior to version 4.1.64. The filter_type request value in ItemController::element() is improperly interpolated into the SQL query without adequate quoting or escaping, allowing remote attackers to execute arbitrary database queries. Updating the Zoo extension to the latest patched version is strongly recommended.
Azərbaycanca: Bu boşluq YooTheme Zoo Joomla genişlənməsinin 4.1.64-dən əvvəlki versiyalarında aşkarlanmış autentifikasiyasız SQL inyeksiya zəifliyidir. ItemController::element() funksiyasında filter_type sorğu parametri düzgün təmizlənmədən SQL sorğusuna daxil edilir ki, bu da uzaqdan hücumçuya verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. Zoo genişlənməsini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the YooTheme Zoo extension are affected by CVE-2026-74804?
This unauthenticated SQL injection vulnerability exists in YooTheme Zoo Joomla extension versions prior to 4.1.64.
Is authentication required to exploit CVE-2026-74804?
No, this is an unauthenticated SQL injection vulnerability, meaning it can be exploited by a remote attacker without any login credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.