AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66492

MEDIUM · CVSS 6.1 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Phoca Commander extension for Joomla versions 1.0.0 to 6.1.3 is vulnerable to a path traversal issue that allows attackers to manipulate file upload paths, potentially leading to unauthorized file access on the server. Organizations using this extension should prioritize patching or mitigating this vulnerability to prevent potential data exposure or system compromise. This is particularly relevant for web administrators and developers managing Joomla sites with the affected extension.

CVE
CVE-2026-66492
Severity
MEDIUM
CVSS
6.1
EPSS
0.37%

Original NVD Description

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.