VYPR

Phoca Cart

by Phoca.cz

CVEs (1)

  • CVE-2026-74251CriAug 16, 2026
    risk 0.60cvss epss

    Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without…