Reflected XSS Vulnerability in Phoca Commander by Phoca.cz
CVE-2026-65764
5.1MEDIUM
What is CVE-2026-65764?
The Phoca Commander Joomla extension contains a reflected XSS vulnerability due to improper validation of user inputs. This security flaw allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, data theft, or defacement of the website. It is crucial for administrators using affected versions 5.0.0 to 6.1.1 to implement appropriate input validation and user data sanitization measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Phoca Commander extension for Joomla 5.0.0-6.1.1
