CVE-2026-74251Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without parameterization or escaping. An unauthenticated attacker can inject arbitrary SQL through these parameters, enabling full database extraction via time-based blind techniques.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-16: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-16: 108-16
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • ADK Cyber@ADKCyber
    Disclosure

    High-severity SQL injection (CVSS 9.3) affects Phoca Cart Joomla extension 5.0.0-6.1.6. Users should review and update promptly. https://nvd.nist.gov/vuln/detail/CVE-2026-74251 https://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/lpCpei11xp

    Post summary

    The tweet announces a high‑severity SQL injection vulnerability (CVE‑2026‑74251) affecting Phoca Cart Joomla, and urges users to update.

    0000064
    93 followersView on X

Explore more