CVE-2026-76569: Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
Published Aug 20, 2026
·Updated
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
Affected Software
1 affected component
phoca.cz/Phoca Download>=5.0.0<=6.1.4
Event History
Aug 20, 2026
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
DescriptionWeakness
Frequently Asked Questions
1
How can I determine whether my deployment is in scope?
Deployments of Phoca Download from version 5.0.0 through 6.1.4 are identified as affected.
2
Which request input is involved?
The issue is associated with the search GET parameter.