CVE-2026-76565

Published Aug 20, 2026

Last updated an hour ago

CVSS medium 5.3
Joomla
Phoca Cart

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-76565 is identified as a reflected Cross-Site Scripting (XSS) vulnerability found within the Phoca Cart extension for Joomla. This flaw specifically impacts versions 5.0.0 through 6.1.7 of the extension. The vulnerability stems from improper output encoding of the `price_from` and `price_to` filter parameters, which are reflected directly into HTTP responses. An attacker can exploit this by crafting a malicious URL containing a JavaScript payload embedded within these parameters. When an authenticated or unauthenticated user visits this crafted URL, the arbitrary JavaScript code can be executed in their browser session. This vulnerability is categorized under CWE-79, which addresses improper neutralization of input during web page generation.

Description
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
Source
security@joomla.org
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

Weaknesses

security@joomla.org
CWE-79

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

References

Sources include official advisories and independent security research.