SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65764

MEDIUM · CVSS 5.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Phoca Commander versions 5.0.0 to 6.1.1 are vulnerable to a reflected cross-site scripting (XSS) attack due to improper validation of user inputs. This vulnerability allows attackers to inject malicious scripts that can execute in the context of the user's browser, potentially leading to session hijacking or data theft. Joomla administrators using these versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-65764
Severity
MEDIUM
CVSS
5.1
EPSS
0.26%

Original NVD Description

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.