SQL Injection Vulnerability in Phoca Cart by Joomla Extension
CVE-2026-74251
9.3CRITICAL
What is CVE-2026-74251?
The Phoca Cart extension for Joomla contains a vulnerability that allows unauthenticated attackers to exploit specific GET parameters ('a[]' and 's[]') on the public shop items page. By manipulating these parameters, attackers can create unfiltered SQL queries, leading to unauthorized access to sensitive database information. This vulnerability poses a significant risk as it can facilitate complete database extraction using time-based blind SQL injection methods, endangering the security and integrity of the affected Joomla websites.
Affected Version(s)
Phoca Cart extension for Joomla 5.0.0-6.1.16
