6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.
Basic Information
ID
CVE-2026-23900
Source
Joomla
Published
Apr 11, 2026 at 12:52
Modified
Apr 13, 2026 at 17:43
Affected Product
Vendor
phoca.cz
Product
phoca.cz - Phoca Maps for Joomla
Version
5.0.0-6.0.2
Affected Versions
phoca.cz phoca.cz - Phoca Maps for Joomla 5.0.0-6.0.2