VYPR
Vendor

Phoca.cz

Products
5
CVEs
10
Across products
10
Status
Private

Products

5

Recent CVEs

10
  • CVE-2026-74251CriAug 16, 2026
    risk 0.60cvss epss 0.00

    Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without…

  • CVE-2026-57828HigJul 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

  • CVE-2026-66491HigAug 7, 2026
    risk 0.53cvss epss 0.00

    Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.

  • CVE-2026-66493MedAug 7, 2026
    risk 0.42cvss epss 0.00

    Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.

  • CVE-2026-23900MedApr 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.

  • CVE-2026-66492MedAug 7, 2026
    risk 0.40cvss epss 0.00

    Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.

  • CVE-2026-76565MedAug 20, 2026
    risk 0.34cvss epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

  • CVE-2026-65764MedJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.

  • CVE-2026-65763MedJul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability.

  • CVE-2026-65762MedJul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.