SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76569

MEDIUM · CVSS 5.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Phoca Download extension for Joomla versions 5.0.0 to 6.1.4 is vulnerable to reflected cross-site scripting (XSS) attacks through the search GET parameter. This vulnerability could allow an attacker to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or session hijacking. Joomla site administrators using the affected versions should prioritize patching or updating to mitigate this risk.

CVE
CVE-2026-76569
Severity
MEDIUM
CVSS
5.3
EPSS
0.26%

Original NVD Description

Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4