Reflected XSS Vulnerability in Phoca Download by Phoca.cz
CVE-2026-76569
5.3MEDIUM
What is CVE-2026-76569?
A reflected XSS vulnerability has been identified in the Phoca Download extension used for Joomla. Malicious actors can exploit this flaw through the search GET parameter, potentially executing arbitrary JavaScript in the context of the user's browser, leading to unauthorized access and data exposure. Users of Phoca Download versions 5.0.0 to 6.1.4 should take immediate action to mitigate risks associated with this vulnerability.
Affected Version(s)
Phoca Download extension for Joomla 5.0.0-6.1.4
