SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76565

MEDIUM · CVSS 5.3 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Phoca Cart extension for Joomla versions 5.0.0 to 6.1.7 is vulnerable to reflected cross-site scripting (XSS) attacks through the price_from and price_to filter parameters. This vulnerability could allow an attacker to execute arbitrary JavaScript in the context of a user's browser, potentially leading to session hijacking or data theft. Joomla administrators and web developers using this extension should prioritize patching or mitigating this vulnerability to protect their users.

CVE
CVE-2026-76565
Severity
MEDIUM
CVSS
5.3
EPSS
0.32%

Original NVD Description

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7