YOOtheme and Joomla 3
Removed Joomla 3 and 4 support in YOOtheme Pro 5.0 in January 2026, yet keeps a 4.5.x line for Joomla 3 that received all four 2026 security fixes in August. The ZOO installation page still lists Joomla 3.x as a requirement.
Joomla extensions covered: YOOtheme Pro, ZOO. YOOtheme website
What they said
“For end users, support for Joomla 3 and 4 has been removed.”
Said 13 Jan 2026Read it on their siteChecked 2 Oct 2026
What they did
YOOtheme Pro 4.3.7 fixes the installer script for Joomla 3
YOOtheme Pro 4.4.11 ships a Joomla 3 fix
YOOtheme Pro 4.4.12 fixes a regression in Joomla 3
YOOtheme Pro 4.5.3 fixes a regression in Joomla 3
YOOtheme Pro 4.5.34 backports all four 2026 security fixes to the Joomla 3 line
YOOtheme Pro 4.5.35 repairs a regression introduced by 4.5.34
The ZOO installation page lists "Requirements: Joomla 3.x+"
Known Joomla 3 vulnerabilities
- High
YOOtheme Pro (yootheme) below 4.5.34 - Authenticated SQL Injection (CVSS 8.6), Arbitrary File Read (CVSS 7.0) and Broken Access Control (CVSS 5.1)
Affected: < 4.5.34
- High
YOOtheme Pro (yootheme) 5.0.0 to 5.0.40 - Authenticated SQL Injection (CVSS 8.6) and Arbitrary File Read (CVSS 7.0)
Affected: ≥ 5.0.0 and < 5.0.41
- High
ZOO (com_zoo) 4.1.65 - Unauthenticated Stored XSS (CVSS 8.6), Unauthenticated Arbitrary Directory Listing (6.9), Reflected XSS and Open Redirect (5.3), and Missing Front-End CSRF Protection
Affected: ≥ 4.1.65 and < 4.1.66
CVE-2026-76611, CVE-2026-76612, CVE-2026-77028, CVE-2026-77029
- High
YOOtheme Pro (location) below 4.5.34 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value (CVSS 7.5)
Affected: ≥ 2.0.0 and < 4.5.34
Our coverage
- A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.
See which of your sites run YOOtheme Pro
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.