Description
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
Published: 2026-08-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a reflected Cross‑Site Scripting flaw in Phoca Cart for Joomla. An attacker can embed malicious script payloads via the price_from and price_to query parameters. When a vulnerable site loads the URL, the unescaped user supplied input appears in the response, allowing an attacker to run JavaScript in the user’s browser. The flaw is categorized as CWE‑79 and could enable cookie theft, defacement, or session hijack for anyone visiting the infected page.

Affected Systems

All Joomla installations that use the Phoca Cart extension with a version between 5.0.0 and 6.1.7 inclusive are affected. The vendor is phoca.cz. The extension functions as an e‑commerce add‑on for Joomla websites.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate overall risk. The EPSS score of less than 1% points to a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is through crafted URL requests that an unsuspecting site visitor or an attacker‑controlled link might follow. Because the flaw operates in the browser, it requires an active user context to cause damage.

Generated by OpenCVE AI on August 20, 2026 at 21:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Phoca Cart to the latest version (>=6.1.8) to remove the XSS vulnerability
  • Sanitize or escape price_from and price_to input parameters if an upgrade cannot be performed immediately
  • Deploy a web application firewall or Joomla security plugin that blocks malicious script injections in query strings

Generated by OpenCVE AI on August 20, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Phoca
Phoca phoca Cart Extension For Joomla
Vendors & Products Phoca
Phoca phoca Cart Extension For Joomla

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
Title Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Phoca Phoca Cart Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-21T04:44:55.904Z

Reserved: 2026-08-19T13:27:07.456Z

Link: CVE-2026-76565

cve-icon Vulnrichment

Updated: 2026-08-20T15:22:53.290Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T08:16:47.900

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-76565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')