Reflected XSS Vulnerability in Phoca Commander by Phoca.cz
CVE-2026-65764

5.1MEDIUM

Key Information:

Vendor

Phoca.cz

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65764?

The Phoca Commander Joomla extension contains a reflected XSS vulnerability due to improper validation of user inputs. This security flaw allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, data theft, or defacement of the website. It is crucial for administrators using affected versions 5.0.0 to 6.1.1 to implement appropriate input validation and user data sanitization measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Phoca Commander extension for Joomla 5.0.0-6.1.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof ZajÄ…c, CERT PL
.