PatchSiren

phoca.cz CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM phoca.cz CVE published 2026-07-27

CVE-2026-65765

A Path Traversal vulnerability exists in Phoca Commander 1.0.0-6.1.1, a Joomla extension from phoca.cz. The vulnerability is caused by improper limitation of paths for save and download actions, leading to path traversal vulnerabilities. The CVE record was published on 2026-07-27T09:16:37.923Z and has not been modified since then. This vulnerability allows attackers to traverse the file system, potentiall [truncated]

MEDIUM phoca.cz CVE published 2026-07-27

CVE-2026-65764

The CVE record for CVE-2026-65764 was published on 2026-07-27T09:16:37.790Z and has not been modified since then. The NVD entry is currently Received. This reflected XSS vulnerability exists in Phoca Commander 5.0.0-6.1.1 due to improper validation of user inputs. Users of Joomla Extension - phoca.cz - Phoca Commander 5.0.0-6.1.1 should be aware of this vulnerability and take necessary actions to mitigate [truncated]

CRITICAL phoca.cz CVE published 2026-07-11

CVE-2026-57828

CVE-2026-57828 is an authenticated arbitrary file upload vulnerability in Joomla's Phoca Downloads extension. This vulnerability allows registered users to upload executable files, potentially leading to full remote code execution (RCE). The vulnerability has a CVSS score of 9 and is classified as CRITICAL. Administrators and users of Joomla's Phoca Downloads extension should be aware of this vulnerabilit [truncated]