VYPR

Phoca Downloads

by Phoca.cz

CVEs (1)

  • CVE-2026-57828HigJul 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.