Search Results (14 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-76565 1 Phoca 1 Phoca Cart Extension For Joomla 2026-08-21 N/A
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
CVE-2026-76569 1 Phoca 1 Phoca Download Extension For Joomla 2026-08-21 N/A
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
CVE-2026-76564 1 Phoca 1 Phoca Cart Extension For Joomla 2026-08-21 N/A
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
CVE-2026-57828 1 Phoca 2 Download, Phoca Download Extension For Joomla 2026-08-19 8.8 High
Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
CVE-2026-74251 1 Phoca 1 Phoca Cart Extension For Joomla 2026-08-17 N/A
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database extraction via time-based blind techniques.
CVE-2026-66493 1 Phoca 1 Phoca Commander Extension For Joomla 2026-08-08 N/A
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.
CVE-2026-66492 1 Phoca 1 Phoca Commander Extension For Joomla 2026-08-08 N/A
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.
CVE-2026-66491 1 Phoca 1 Phoca Commander Extension For Joomla 2026-08-08 N/A
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.
CVE-2026-65763 1 Phoca 1 Phoca Maps Extension For Joomla 2026-07-28 N/A
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-65762 1 Phoca 1 Phoca Guestbook Extension For Joomla 2026-07-28 N/A
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-65764 1 Phoca 1 Phoca Commander Extension For Joomla 2026-07-27 N/A
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
CVE-2026-65765 1 Phoca 1 Phoca Commander Extension For Joomla 2026-07-27 N/A
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.
CVE-2009-0702 2 Joomla, Phoca 2 Joomla, Com Phocadocumentation 2026-04-23 N/A
SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php.
CVE-2026-23900 2 Phoca, Phoca.cz 2 Maps, Phoca.cz - Phoca Maps For Joomla 2026-04-17 6.5 Medium
Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.