Junglewise Threat Intelligence

CVE-2026-76569: Phoca Download reflected XSS in search parameter

CVE-2026-76569 · Severity: info · Published 2026-08-20

Executive brief

Phoca Download is a Joomla extension for managing downloadable files and content. A reflected cross-site scripting (XSS) vulnerability in the search function allows attackers to inject malicious scripts that execute in users' browsers when they click a crafted link, potentially compromising user sessions or redirecting visitors to malicious sites.

Technical details

A reflected XSS vulnerability exists in Phoca Download versions 5.0.0 through 6.1.4 in the search GET parameter. The vulnerability occurs because user-supplied input from the search parameter is not properly sanitized or encoded before being reflected in the HTTP response. An attacker can craft a malicious URL containing JavaScript code in the search parameter, and when a victim visits the link, the script executes in their browser with the context of the vulnerable application. No authentication is required, and the attack vector is network-based via a crafted URL. A patch is likely available in versions later than 6.1.4.

Affected products

  • phoca.cz Phoca Download 5.0.0-6.1.4

Timeline

  • 2026-08-20: disclosed

References

Related threats