CVE-2026-23900: Extension - phoca.cz - Stored XSS vectors in Phoca Maps component 5.0.0 - 6.0.2 for Joomla
Published Apr 11, 2026
·Updated
Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.
Affected Software
2 affected components
phoca.cz Phoca Maps>=5.0.0<=6.0.2
Phoca maps>=5.0.0<=6.0.2
Event History
Apr 11, 2026
CVE Published
via MITRE·12:52 PM
Data Sourced
via MITRE·12:52 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-23900?
The severity of CVE-2026-23900 is medium with a CVSS score of 6.5.
2
How do I fix CVE-2026-23900?
To fix CVE-2026-23900, upgrade the Phoca Maps component to version 6.0.3 or later.
3
What types of vulnerabilities does CVE-2026-23900 include?
CVE-2026-23900 includes various stored XSS vulnerabilities in the maps and icon rendering logic.
4
What software is affected by CVE-2026-23900?
CVE-2026-23900 affects Phoca Maps component versions 5.0.0 to 6.0.2 for Joomla.
5
When was CVE-2026-23900 published?
CVE-2026-23900 was published on April 11, 2026.