CVE 6.5 MEDIUM

Extension – phoca.cz – Stored XSS vectors in Phoca Maps component 5.0.0 – 6.0.2 for Joomla_CVE-2026-23900

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.

Basic Information

ID CVE-2026-23900
Source Joomla
Published Apr 11, 2026 at 12:52
Modified Apr 13, 2026 at 17:43

Affected Product

Vendor phoca.cz
Product phoca.cz - Phoca Maps for Joomla
Version 5.0.0-6.0.2
Affected Versions phoca.cz phoca.cz - Phoca Maps for Joomla 5.0.0-6.0.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.