VYPR

Phoca Commander

by Phoca.cz

CVEs (4)

  • CVE-2026-66491HigAug 7, 2026
    risk 0.53cvss epss

    Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.

  • CVE-2026-66493MedAug 7, 2026
    risk 0.42cvss epss

    Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.

  • CVE-2026-66492MedAug 7, 2026
    risk 0.40cvss epss

    Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.

  • CVE-2026-65764MedJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.