CVE-2026-65765: Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.1
Published Jul 27, 2026
·Updated
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.
Affected Software
1 affected component
phoca.cz Phoca Commander>=1.0.0<=6.1.1
Event History
Jul 27, 2026
CVE Published
via MITRE·08:01 AM
Data Sourced
via MITRE·08:01 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65765?
CVE-2026-65765 has a medium severity rating of 6.9 on the CVSS scale.
2
How do I fix CVE-2026-65765?
To fix CVE-2026-65765, update Phoca Commander to the latest version that addresses the path traversal vulnerability.
3
What are the potential consequences of CVE-2026-65765?
Exploitation of CVE-2026-65765 could allow an attacker to access unauthorized files on the server.
4
Which versions of Phoca Commander are affected by CVE-2026-65765?
CVE-2026-65765 affects Phoca Commander versions 1.0.0 through 6.1.1.
5
What type of vulnerability is CVE-2026-65765?
CVE-2026-65765 is classified as a path traversal vulnerability.