Junglewise Threat Intelligence

CVE-2026-76565: Phoca Cart reflected XSS in price filter parameters

CVE-2026-76565 · Severity: info · Published 2026-08-20

Executive brief

Phoca Cart is a Joomla e-commerce extension used to build online stores and shopping cart functionality. The extension contains a reflected cross-site scripting (XSS) vulnerability in its price filtering feature that could allow an attacker to inject malicious scripts into product filter URLs. If a customer clicks a manipulated link, the attacker's JavaScript code could execute in their browser, potentially stealing account credentials or session data.

Technical details

The vulnerability is a reflected XSS flaw in the price_from and price_to filter parameters of Phoca Cart. These parameters are not properly sanitized or output-encoded before being displayed on the page, allowing an attacker to inject arbitrary HTML and JavaScript. The attack vector is network-based and does not require authentication; it relies on social engineering (victim clicking a malicious link). An attacker can craft a URL with JavaScript payload in the filter parameters to execute code in the victim's browser context. The vulnerability affects versions 5.0.0 through 6.1.7.

Affected products

  • phoca.cz Phoca Cart 5.0.0-6.1.7

Timeline

  • 2026-08-20: disclosed

References

Related threats