Reflected XSS Vulnerability in Phoca Download by Phoca.cz
CVE-2026-76569
Key Information:
- Vendor
Phoca.cz
- Vendor
- CVE Published:
- 20 August 2026
Badges
What is CVE-2026-76569?
A reflected XSS vulnerability has been identified in the Phoca Download extension used for Joomla. Malicious actors can exploit this flaw through the search GET parameter, potentially executing arbitrary JavaScript in the context of the user's browser, leading to unauthorized access and data exposure. Users of Phoca Download versions 5.0.0 to 6.1.4 should take immediate action to mitigate risks associated with this vulnerability.
Affected Version(s)
Phoca Download extension for Joomla 5.0.0-6.1.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
