CVE-2026-66491
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
CVSS Score
0.0
EPSS Score
0.3%
EPSS Percentile
24th
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.
| CWE | CWE-22 |
| Vendor | phoca.cz |
| Product | phoca commander extension for joomla |
| Published | Aug 7, 2026 |
| Last Updated | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for phoca.cz phoca commander extension for joomla
Be the first to know when new unknown vulnerabilities affecting phoca.cz phoca commander extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
phoca.cz / Phoca Commander extension for Joomla
1.0.0-6.1.3
Credits
Toan Le