CVE-2026-74251
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database extraction via time-based blind techniques.
| CWE | CWE-89 |
| Vendor | phoca.cz |
| Product | phoca cart extension for joomla |
| Published | Aug 16, 2026 |
| Last Updated | Aug 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for phoca.cz phoca cart extension for joomla
Be the first to know when new unknown vulnerabilities affecting phoca.cz phoca cart extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
phoca.cz / Phoca Cart extension for Joomla
5.0.0-6.1.6