Reflected XSS Vulnerability in Phoca Download by Phoca.cz
CVE-2026-76569

5.3MEDIUM

Key Information:

Vendor

Phoca.cz

Vendor
CVE Published:
20 August 2026

What is CVE-2026-76569?

A reflected XSS vulnerability has been identified in the Phoca Download extension used for Joomla. Malicious actors can exploit this flaw through the search GET parameter, potentially executing arbitrary JavaScript in the context of the user's browser, leading to unauthorized access and data exposure. Users of Phoca Download versions 5.0.0 to 6.1.4 should take immediate action to mitigate risks associated with this vulnerability.

Affected Version(s)

Phoca Download extension for Joomla 5.0.0-6.1.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Toan Le
.