Description
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability.
Published: 2026-07-23
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Phoca Maps 5.0.0 through 6.0.4 contains a reflected cross‑site scripting flaw caused by improper validation of user supplied text. When an attacker crafts a URL or submits input that the extension inserts back into the response without adequate escaping, the browser will execute the embedded script in the context of the victim’s session. This can lead to theft of session cookies, defacement or the injection of further malicious payloads. The weakness is a classic CWE‑79 scenario.

Affected Systems

The vulnerability affects the Joomla extension "Phoca Maps" provided by phoca.cz, specifically all builds from 5.0.0 to 6.0.4. Users running any of these versions on a Joomla site are exposed.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1% signals a low probability of exploitation in the wild, and the item is not listed in the CISA KEV catalog. The flaw is client‑side; an attacker can invoke it by luring a user to a malicious link or submitting a crafted form, and it does not require authentication. While the threat is moderate, the impact on user trust and potential credential compromise warrants swift action.

Generated by OpenCVE AI on August 3, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Phoca Maps to a released version that removes the reflected XSS vulnerability, preferably 6.0.5 or later
  • If an update is not immediately possible, modify the extension or its configuration to remove the unescaped input handling or apply an input‑sanitization layer around the vulnerable fields
  • Continuously review site content and logs for signs of script injection and enforce stricter content‑security policies to mitigate any residual risk

Generated by OpenCVE AI on August 3, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Phoca
Phoca phoca Maps Extension For Joomla
Vendors & Products Phoca
Phoca phoca Maps Extension For Joomla

Fri, 24 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability. Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability.
Title Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability.
Title Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Phoca Phoca Maps Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-24T07:17:15.853Z

Reserved: 2026-07-22T20:46:13.953Z

Link: CVE-2026-65763

cve-icon Vulnrichment

Updated: 2026-07-23T19:05:25.849Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T18:17:02.023

Modified: 2026-07-24T08:16:27.413

Link: CVE-2026-65763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')