SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65762

MEDIUM · CVSS 5.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Phoca Guestbook extension for Joomla versions 5.0.0 to 6.1.0 is vulnerable to a reflected cross-site scripting (XSS) attack due to improper validation of user inputs. This vulnerability could allow attackers to inject malicious scripts, potentially compromising user sessions or redirecting users to malicious sites. Joomla administrators using affected versions should prioritize patching this vulnerability to protect their users and maintain the integrity of their web applications.

CVE
CVE-2026-65762
Severity
MEDIUM
CVSS
5.1
EPSS
0.34%

Original NVD Description

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.