๐Ÿ” CVE Alert

CVE-2026-74251

UNKNOWN 0.0

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database extraction via time-based blind techniques.

CWE CWE-89
Vendor phoca.cz
Product phoca cart extension for joomla
Published Aug 16, 2026
Last Updated Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for phoca.cz phoca cart extension for joomla

Be the first to know when new unknown vulnerabilities affecting phoca.cz phoca cart extension for joomla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

phoca.cz / Phoca Cart extension for Joomla
5.0.0-6.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phoca.cz: https://www.phoca.cz/phocacart