Reflected XSS Vulnerability in Phoca Guestbook by Phoca
CVE-2026-65762

5.1MEDIUM

Key Information:

Vendor

Phoca.cz

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65762?

The Phoca Guestbook Joomla extension suffers from a reflected XSS vulnerability due to improper validation of user inputs. As a result, an attacker could exploit this flaw to execute arbitrary JavaScript code in the context of a vulnerable user session, potentially leading to unauthorized actions on behalf of the user or theft of sensitive information.

Affected Version(s)

Phoca Guestbook extension for Joomla 1.0.0-6.1.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof ZajÄ…c, CERT PL
.