A Path Traversal vulnerability exists in Phoca Commander 1.0.0-6.1.1, a Joomla extension from phoca.cz. The vulnerability is caused by improper limitation of paths for save and download actions, leading to path traversal vulnerabilities. The CVE record was published on 2026-07-27T09:16:37.923Z and has not been modified since then. This vulnerability allows attackers to traverse the file system, potentiall [truncated]
The CVE record for CVE-2026-65764 was published on 2026-07-27T09:16:37.790Z and has not been modified since then. The NVD entry is currently Received. This reflected XSS vulnerability exists in Phoca Commander 5.0.0-6.1.1 due to improper validation of user inputs. Users of Joomla Extension - phoca.cz - Phoca Commander 5.0.0-6.1.1 should be aware of this vulnerability and take necessary actions to mitigate [truncated]
CVE-2026-57828 is an authenticated arbitrary file upload vulnerability in Joomla's Phoca Downloads extension. This vulnerability allows registered users to upload executable files, potentially leading to full remote code execution (RCE). The vulnerability has a CVSS score of 9 and is classified as CRITICAL. Administrators and users of Joomla's Phoca Downloads extension should be aware of this vulnerabilit [truncated]