Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76565 | 1 Phoca | 1 Phoca Cart Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 | ||||
| CVE-2026-76569 | 1 Phoca | 1 Phoca Download Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 | ||||
| CVE-2026-76564 | 1 Phoca | 1 Phoca Cart Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 | ||||
| CVE-2026-57828 | 1 Phoca | 2 Download, Phoca Download Extension For Joomla | 2026-08-19 | 8.8 High |
| Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE. | ||||
| CVE-2009-0702 | 2 Joomla, Phoca | 2 Joomla, Com Phocadocumentation | 2025-04-09 | N/A |
| SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php. | ||||
Page 1 of 1.