SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65765

MEDIUM · CVSS 6.9 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Phoca Commander extension for Joomla versions 1.0.0 to 6.1.1 is vulnerable to a path traversal issue, allowing attackers to manipulate file paths for save and download actions. This vulnerability could lead to unauthorized access to sensitive files on the server. Joomla administrators using affected versions should prioritize patching or upgrading to mitigate potential exploitation risks.

CVE
CVE-2026-65765
Severity
MEDIUM
CVSS
6.9
EPSS
0.31%

Original NVD Description

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.