Stored Cross-Site Scripting in Phoca Maps Component by Phoca
CVE-2026-23900

Currently unrated

Key Information:

Vendor

Phoca.cz

Vendor
CVE Published:
11 April 2026

What is CVE-2026-23900?

Several stored Cross-Site Scripting vulnerabilities have been identified in the Phoca Maps component, affecting versions 5.0.0 through 6.0.2. These vulnerabilities arise from improper handling of maps and icon rendering logic, allowing attackers to inject malicious scripts that could execute in the context of users accessing the application. This could potentially lead to the theft of user credentials, session hijacking, or other malicious activities.

Affected Version(s)

phoca.cz - Phoca Maps for Joomla 5.0.0-6.0.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Felipe Monteiro
Leandro Vallim
.