Skip to main content

YOOtheme and Joomla 3

Said stopped, kept shipping

Removed Joomla 3 and 4 support in YOOtheme Pro 5.0 in January 2026, yet keeps a 4.5.x line for Joomla 3 that received all four 2026 security fixes in August. The ZOO installation page still lists Joomla 3.x as a requirement.

Joomla extensions covered: YOOtheme Pro, ZOO. YOOtheme website

What they said

  • “For end users, support for Joomla 3 and 4 has been removed.”

    Said 13 Jan 2026Read it on their siteChecked 2 Oct 2026

What they did

  1. YOOtheme Pro 4.3.7 fixes the installer script for Joomla 3

    Source

  2. YOOtheme Pro 4.4.11 ships a Joomla 3 fix

    Source

  3. YOOtheme Pro 4.4.12 fixes a regression in Joomla 3

    Source

  4. YOOtheme Pro 4.5.3 fixes a regression in Joomla 3

    Source

  5. YOOtheme Pro 4.5.34 backports all four 2026 security fixes to the Joomla 3 line

    Source

  6. YOOtheme Pro 4.5.35 repairs a regression introduced by 4.5.34

    Source

  7. The ZOO installation page lists "Requirements: Joomla 3.x+"

    Source

Known Joomla 3 vulnerabilities

  • High

    YOOtheme Pro (yootheme) below 4.5.34 - Authenticated SQL Injection (CVSS 8.6), Arbitrary File Read (CVSS 7.0) and Broken Access Control (CVSS 5.1)

    Affected: < 4.5.34

    CVE-2026-76613, CVE-2026-75115, CVE-2026-77997

  • High

    YOOtheme Pro (yootheme) 5.0.0 to 5.0.40 - Authenticated SQL Injection (CVSS 8.6) and Arbitrary File Read (CVSS 7.0)

    Affected: ≥ 5.0.0 and < 5.0.41

    CVE-2026-76613, CVE-2026-75115

  • High

    ZOO (com_zoo) 4.1.65 - Unauthenticated Stored XSS (CVSS 8.6), Unauthenticated Arbitrary Directory Listing (6.9), Reflected XSS and Open Redirect (5.3), and Missing Front-End CSRF Protection

    Affected: ≥ 4.1.65 and < 4.1.66

    CVE-2026-76611, CVE-2026-76612, CVE-2026-77028, CVE-2026-77029

  • High

    YOOtheme Pro (location) below 4.5.34 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value (CVSS 7.5)

    Affected: ≥ 2.0.0 and < 4.5.34

    CVE-2026-77996

Our coverage

See which of your sites run YOOtheme Pro

Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.

Audit a Joomla 3 site free