Path Traversal Vulnerability in Phoca Commander by Phoca.cz
CVE-2026-65765

6.9MEDIUM

Key Information:

Vendor

Phoca.cz

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65765?

A path traversal vulnerability exists in Phoca Commander that allows attackers to manipulate path limitations during save and download actions. By exploiting this flaw, individuals can access restricted directories and files on the server, potentially leading to unauthorized file disclosure. It is crucial for users to update their installations to mitigate risks associated with this security issue.

Affected Version(s)

Phoca Commander extension for Joomla 1.0.0-6.1.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Revanth Meesala
.