Description
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
Published: 2026-07-27
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper validation of user inputs within the Phoca Commander Joomla extension enables a reflected cross‑site scripting flaw. The vulnerability occurs when unsanitized data supplied by the user is reflected back in the page, allowing an attacker to inject arbitrary JavaScript that executes in the context of the victim’s browser. This could enable attackers to deface the site, harvest credentials, or perform social engineering tactics.

Affected Systems

The flaw affects Joomla sites that use the Phoca Commander extension versions 5.0.0 through 6.1.1. Any site that has installed this extension within the specified version range is at risk, regardless of the Joomla core version. No other products are listed.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, and the EPSS score of less than 1% suggests a relatively low current exploitation probability, although active exploitation cannot be ruled out. The vulnerability can be leveraged by sending a crafted HTTP request or form submission that contains malicious query parameters; the extension then reflects the input without proper encoding, exposing the user’s browser to script execution.

Generated by OpenCVE AI on August 3, 2026 at 17:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Phoca Commander extension to a version newer than 6.1.1 (for example, 6.1.2 or later) from the vendor’s website.
  • Verify that all reflected input fields are now rendering user data with proper encoding or sanitization to prevent script execution.
  • If an update cannot be applied immediately, implement a site‑wide Content Security Policy that restricts the loading of scripts to trusted sources and mitigates the impact of any injected code.

Generated by OpenCVE AI on August 3, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Phoca
Phoca phoca Commander Extension For Joomla
Vendors & Products Phoca
Phoca phoca Commander Extension For Joomla

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
Title Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.1.1
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Phoca Phoca Commander Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-27T12:56:14.032Z

Reserved: 2026-07-22T20:46:13.953Z

Link: CVE-2026-65764

cve-icon Vulnrichment

Updated: 2026-07-27T10:25:06.756Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T09:16:37.790

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-65764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')