AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66493

MEDIUM · CVSS 6.4 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A path traversal vulnerability exists in the Phoca Commander extension for Joomla, affecting versions 1.0.0 to 6.1.3, allowing unauthorized access to file system paths during delete, copy, and move operations. This could enable attackers to manipulate files outside of the intended directories, potentially leading to data exposure or system compromise. Joomla site administrators using this extension should prioritize patching or mitigating this vulnerability to safeguard their systems.

CVE
CVE-2026-66493
Severity
MEDIUM
CVSS
6.4
EPSS
0.31%

Original NVD Description

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.