What is CVE-2026-74251?
This vulnerability exists in Phoca Cart 5.0.0-6.1.6 Joomla extension's public shop items page. An unauthenticated attacker can perform SQL injection by injecting raw data into SQL WHERE clauses via the 'a[]' (attribute) and 's[]' (specification) GET array parameters. Users should immediately apply the security update or temporarily filter these parameters.
Azərbaycanca: Bu boşluq Phoca Cart 5.0.0-6.1.6 Joomla genişlənməsinin ictimai mağaza səhifəsində aşkarlanıb. Autentifikasiya olunmamış hücumçu 'a[]' (attribute) və 's[]' (specification) GET massiv parametrləri vasitəsilə SQL WHERE şərtlərinə xam məlumat əlavə edərək SQL injection həyata keçirə bilər. İstifadəçilər dərhal təhlükəsizlik yeniləməsini tətbiq etməli və ya müvəqqəti olaraq bu parametrləri filtrləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of Phoca Cart are affected by the CVE-2026-74251 SQL injection vulnerability?
The CVE-2026-74251 vulnerability exists in Phoca Cart versions 5.0.0 through 6.1.6.
Does exploiting CVE-2026-74251 require authentication?
No, an unauthenticated attacker can perform SQL injection on the public shop items page via the 'a[]' and 's[]' GET parameters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.