Stored Cross-Site Scripting in Phoca Maps Component by Phoca
CVE-2026-23900
Currently unrated
What is CVE-2026-23900?
Several stored Cross-Site Scripting vulnerabilities have been identified in the Phoca Maps component, affecting versions 5.0.0 through 6.0.2. These vulnerabilities arise from improper handling of maps and icon rendering logic, allowing attackers to inject malicious scripts that could execute in the context of users accessing the application. This could potentially lead to the theft of user credentials, session hijacking, or other malicious activities.
Affected Version(s)
phoca.cz - Phoca Maps for Joomla 5.0.0-6.0.2
