Executive brief
Phoca Maps is a Joomla extension used to display interactive maps and location markers on websites. A security vulnerability in how the software handles map and icon data allows attackers to inject malicious scripts into the site. If exploited, this could lead to unauthorized actions being performed in a user's browser, potentially compromising user sessions or defacing website content.
Technical details
Phoca Maps versions 5.0.0 through 6.0.2 are vulnerable to multiple stored Cross-Site Scripting (XSS) attacks (CWE-79). The vulnerability exists within the rendering logic for maps and icons, where user-supplied input is improperly neutralized before being stored and subsequently displayed to other users. An attacker can exploit this by submitting malicious JavaScript through map or icon configuration fields. When a site visitor or administrator views the affected map, the script executes in their browser context. This can lead to session hijacking, unauthorized administrative actions, or redirection to malicious sites.
Affected products
- Phoca Phoca Maps 5.0.0-6.0.2
Timeline
- 2026-04-11: disclosed: Initial disclosure by Joomla! Project
- 2026-04-11: advisory: NVD published the CVE entry