Reflected XSS Vulnerability in Phoca Maps by Joomla Extension Vendor
CVE-2026-65763

5.1MEDIUM

Key Information:

Vendor

Phoca.cz

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65763?

The Phoca Maps Joomla extension is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability due to improper validation of user inputs. This flaw can be exploited by attackers to inject malicious scripts into webpages viewed by unsuspecting users. When users interact with the compromised application, they may unknowingly execute the injected scripts, potentially leading to unauthorized access and data theft.

Affected Version(s)

Phoca Maps extension for Joomla 1.0.0-6.0.9

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof ZajÄ…c, CERT PL
.