SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76564

HIGH · CVSS 8.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Phoca Cart extension for Joomla is vulnerable to a stored cross-site scripting (XSS) attack through the User-Agent header in the Admin Order View, affecting versions 5.0.0 to 6.1.7. This vulnerability could allow an attacker to execute arbitrary scripts in the context of an admin user's session, potentially compromising sensitive data or administrative controls. Joomla site administrators using the affected versions should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-76564
Severity
HIGH
CVSS
8.6
EPSS
0.32%

Original NVD Description

Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7