CVE-2026-76564: Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
Published Aug 20, 2026
·Updated
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
Affected Software
1 affected component
phoca/cart>=5.0.0<=6.1.7
Event History
Aug 20, 2026
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
DescriptionWeakness
Frequently Asked Questions
1
Which Phoca Cart versions are affected?
The affected version range is 5.0.0 through 6.1.7.
2
What must occur for the stored script to execute?
An attacker can supply a malicious User-Agent header, and the stored content is relevant when an administrator views an order in the admin order view.