CyberRota Analysis
AI-GeneratedThe Phoca Commander extension for Joomla versions 1.0.0 to 6.1.1 is vulnerable to a path traversal issue, allowing attackers to manipulate file paths for save and download actions. This vulnerability could lead to unauthorized access to sensitive files on the server. Joomla administrators using affected versions should prioritize patching or upgrading to mitigate potential exploitation risks.
CVE
CVE-2026-65765
Severity
MEDIUM
CVSS
6.9
EPSS
0.31%
Original NVD Description
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.