CVE-2026-76565: Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
Published Aug 20, 2026
·Updated
Joomla Extension - phoca.cz - Reflected XSS via pricefrom & priceto filter parameters in Phoca Cart 5.0.0-6.1.7
Affected Software
1 affected component
phoca.cz Phoca Cart>=5.0.0<=6.1.7
Event History
Aug 20, 2026
CVE Published
via MITRE·07:27 AM
Data Sourced
via MITRE·07:27 AM
DescriptionWeakness
Frequently Asked Questions
1
Which inputs are involved in this issue?
The reflected XSS is associated with the price_from and price_to filter parameters.
2
What Phoca Cart versions are identified as affected?
Phoca Cart versions 5.0.0 through 6.1.7 are identified as affected.