
🔥 CyberForge CVE of the Day #030 🚨 CVE-2026-76564 — Phoca Cart has patched a High-severity stored XSS vulnerability in its Joomla administrator order view. An unauthenticated attacker can poison an order using a crafted HTTP User-Agent. The value is stored and executes when privileged staff open the order—placing malicious script inside the trusted Joomla administrator origin. 🔑 Key details: ⭐ Severity: High — CVSS 8.6 ⭐ CWE-79 — Stored XSS ⭐ Affected: Phoca Cart 5.0.0–6.1.7 ⭐ Fixed: Phoca Cart 6.1.8 ⭐ Attacker authentication: None ⭐ User interaction: Administrator opens the poisoned order 🎯 Potential impact: 🔹 Customer and order-data access 🔹 Same-origin actions using the administrator session 🔹 Order, account or configuration manipulation 🔹 Persistent execution against multiple staff members ⚠️ This is not direct server-side RCE, but abuse of a privileged browser session could lead to shop takeover depending on the administrator’s permissions and available functionality. 🛡 Defenders: ✅ Upgrade to official Phoca Cart 6.1.8 or later now. ✅ Avoid opening suspicious orders in an unpatched backend. ✅ Hunt stored User-Agent values and web/proxy logs for encoded HTML or JavaScript. ✅ Audit Joomla users, ACLs, extensions, templates and configuration changes. ✅ Review custom overrides and exports that render User-Agent metadata. ✅ Verify the running extension carefully—the public 6.1.8 tag contained stale 6.1.7 version text during review. 🔎 No public executable PoC, confirmed active exploitation or CISA KEV listing was identified as of 21 August 2026. EPSS remains pending. 🔗 Full advisory: https://github.com/advisories/GHSA-98mw-pj3j-99v2 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-76564 #CyberForge #CVEOfTheDay #CVE202676564 #PhocaCart #Joomla #StoredXSS #XSS #AppSec #BlueTeam #ThreatHunting #PatchNow
Post summary
The advisory announces a high‑severity stored XSS vulnerability in Phoca Cart, supplies patch information and mitigation steps, and confirms no active exploitation or PoC yet.



