PatchSiren

phoca.cz CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL phoca.cz CVE published 2026-08-16

CVE-2026-74251

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-16T13:16:57.147Z and has not been modified since then. This critical vulnerability, CVE-2026-74251, affects Joomla users with the Phoca Cart extension installed, specifically versions 5.0.0-6.1.6. The vulnerability allows for unauthenticated SQL injection via attribute filter in Phoca Cart's public [truncated]

MEDIUM phoca.cz CVE published 2026-08-07

CVE-2026-66493

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T09:16:59.300Z and has not been modified since then. The Phoca Commander Joomla Extension, versions 1.0.0-6.1.3, is vulnerable to path traversal attacks due to improper limitation of paths for delete, copy, and move actions. This medium-severity vulnerability, with a CVSS score of 6.4, could allow [truncated]

MEDIUM phoca.cz CVE published 2026-08-07

CVE-2026-66492

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T09:16:59.167Z and has not been modified since then. The Phoca Commander extension for Joomla has a path traversal vulnerability in versions 1.0.0-6.1.3. The vulnerability is caused by improper limitation of paths in the file upload action, leading to a path traversal vulnerability. This may allow [truncated]

HIGH phoca.cz CVE published 2026-08-07

CVE-2026-66491

The CVE-2026-66491 record describes an arbitrary file read vulnerability in Phoca Commander 1.0.0-6.1.3, a Joomla extension, due to improper limitation of paths in the getSource function. This vulnerability, with a CVSS score of 8.2, could allow attackers to read arbitrary files. Users of affected versions should verify their installations and consider updating to a patched version. The CVE record was pub [truncated]

MEDIUM phoca.cz CVE published 2026-07-27

CVE-2026-65765

A Path Traversal vulnerability exists in Phoca Commander 1.0.0-6.1.1, a Joomla extension from phoca.cz. The vulnerability is caused by improper limitation of paths for save and download actions, leading to path traversal vulnerabilities. The CVE record was published on 2026-07-27T09:16:37.923Z and has not been modified since then. This vulnerability allows attackers to traverse the file system, potentiall [truncated]

MEDIUM phoca.cz CVE published 2026-07-27

CVE-2026-65764

The CVE record for CVE-2026-65764 was published on 2026-07-27T09:16:37.790Z and has not been modified since then. The NVD entry is currently Received. This reflected XSS vulnerability exists in Phoca Commander 5.0.0-6.1.1 due to improper validation of user inputs. Users of Joomla Extension - phoca.cz - Phoca Commander 5.0.0-6.1.1 should be aware of this vulnerability and take necessary actions to mitigate [truncated]

CRITICAL phoca.cz CVE published 2026-07-11

CVE-2026-57828

CVE-2026-57828 is an authenticated arbitrary file upload vulnerability in Joomla's Phoca Downloads extension. This vulnerability allows registered users to upload executable files, potentially leading to full remote code execution (RCE). The vulnerability has a CVSS score of 9 and is classified as CRITICAL. Administrators and users of Joomla's Phoca Downloads extension should be aware of this vulnerabilit [truncated]