CVE-2026-66492: Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
Published Aug 7, 2026
·Updated
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.
Affected Software
1 affected component
joomla/phoca.cz/phoca commander>=1.0.0<=6.1.3
Event History
Aug 7, 2026
CVE Published
via MITRE·08:03 AM
Data Sourced
via MITRE·08:03 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66492?
CVE-2026-66492 has a risk rating of 45, indicating a moderate severity level.
2
How do I fix CVE-2026-66492?
To mitigate CVE-2026-66492, update to an updated version of Phoca Commander that resolves the path traversal vulnerability.
3
What kind of vulnerability is CVE-2026-66492?
CVE-2026-66492 is a Path Traversal vulnerability affecting Phoca Commander.
4
Which versions of Phoca Commander are affected by CVE-2026-66492?
Phoca Commander versions 1.0.0-6.1.3 are affected by CVE-2026-66492.
5
What consequences can arise from the exploitation of CVE-2026-66492?
Exploitation of CVE-2026-66492 can allow unauthorized access to sensitive files on the server.