Critical severityNVD Advisory· Published Aug 15, 2025· Updated Apr 15, 2026
CVE-2025-54473
CVE-2025-54473
Description
An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- phoca.cznvd
News mentions
0No linked articles in our index yet.