๐Ÿ” CVE Alert

CVE-2026-102775

UNKNOWN 0.0

Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-emptiness only โ€” they are never compared to the stored download_token / order_token values. As a result, any remote user (including a guest with no account at all) can download any customer's digital goods by enumerating sequential id values and supplying arbitrary non-empty tokens.

CWE CWE-639
Vendor phoca.cz
Product phoca cart extension for joomla
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for phoca.cz phoca cart extension for joomla

Be the first to know when new unknown vulnerabilities affecting phoca.cz phoca cart extension for joomla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

phoca.cz / Phoca Cart extension for Joomla
5.0.0-6.1.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phoca.cz: https://www.phoca.cz/