SQL Injection Vulnerability in Phoca Cart by Joomla Extension
CVE-2026-74251
Key Information:
- Vendor
Phoca.cz
- Vendor
- CVE Published:
- 16 August 2026
Badges
What is CVE-2026-74251?
The Phoca Cart extension for Joomla contains a vulnerability that allows unauthenticated attackers to exploit specific GET parameters ('a[]' and 's[]') on the public shop items page. By manipulating these parameters, attackers can create unfiltered SQL queries, leading to unauthorized access to sensitive database information. This vulnerability poses a significant risk as it can facilitate complete database extraction using time-based blind SQL injection methods, endangering the security and integrity of the affected Joomla websites.
Affected Version(s)
Phoca Cart extension for Joomla 5.0.0-6.1.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
