phoca.cz vulnerabilities
8 CVEs tracked
Phoca.cz Joomla extensions appear in our reporting with multiple critical vulnerabilities. The main themes are Reflected XSS due to improper input validation (CVE-2026-65762, CVE-2026-65763, CVE-2026-65764) and critical Path Traversal flaws identified in the Phoca Commander component (CVE-2026-65765, CVE-2026-66491, CVE-2026-66492, CVE-2026-66493). A particularly concerning issue is an unauthenticated SQL injection vulnerability in Phoca Cart (CVE-2026-74251). Defenders should pay special attention to the file operation functions of Phoca Commander and the public interface of Phoca Cart, and immediately update these extensions to the latest versions.
Azərbaycanca: Phoca.cz Joomla genişləndirmələri hesabatlarımızda çoxsaylı kritik boşluqlarla diqqət çəkir. Əsas mövzular istifadəçi girişlərinin düzgün yoxlanılmaması nəticəsində yaranan Reflected XSS (CVE-2026-65762, CVE-2026-65763, CVE-2026-65764) və Phoca Commander komponentində aşkarlanan kritik Path Traversal zəiflikləridir (CVE-2026-65765, CVE-2026-66491, CVE-2026-66492, CVE-2026-66493). Xüsusilə diqqətəlayiq hal, Phoca Cart-da autentifikasiya olmadan istismar edilə bilən SQL injection (CVE-2026-74251) boşluğudur. Müdafiəçilər Phoca Commander-in fayl əməliyyatları funksiyalarına və Phoca Cart-ın ictimai interfeysinə xüsusi diqqət yetirməli, bu genişləndirmələri dərhal ən son versiyalara yeniləməlidirlər.
This vendor's CVEs8
This hub is built from skopnix's own reporting on phoca.cz: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.