Reflected XSS Vulnerability in Phoca Cart by Phoca.cz
CVE-2026-76565
Key Information:
- Vendor
Phoca.cz
- Vendor
- CVE Published:
- 20 August 2026
Badges
What is CVE-2026-76565?
The reflected XSS vulnerability in Phoca Cart versions 5.0.0 to 6.1.7 stems from inadequate validation of input parameters. Specifically, the 'price_from' and 'price_to' parameters can be manipulated to execute malicious scripts in the browser of an unsuspecting user. This vulnerability can lead to data theft, session hijacking, and a host of other security issues for users interacting with vulnerable instances of Phoca Cart.
Affected Version(s)
Phoca Cart extension for Joomla 5.0.0-6.1.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
