CVE-2026-76564General

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-20); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-20: 3Mentions · 2026-08-21: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 108-2008-21
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-203
Disclosure1General2
2026-08-211
Patch1
Full discourse4 posts
  • lee1981@lee1981b
    Patch

    🔥 CyberForge CVE of the Day #030 🚨 CVE-2026-76564 — Phoca Cart has patched a High-severity stored XSS vulnerability in its Joomla administrator order view. An unauthenticated attacker can poison an order using a crafted HTTP User-Agent. The value is stored and executes when privileged staff open the order—placing malicious script inside the trusted Joomla administrator origin. 🔑 Key details: ⭐ Severity: High — CVSS 8.6 ⭐ CWE-79 — Stored XSS ⭐ Affected: Phoca Cart 5.0.0–6.1.7 ⭐ Fixed: Phoca Cart 6.1.8 ⭐ Attacker authentication: None ⭐ User interaction: Administrator opens the poisoned order 🎯 Potential impact: 🔹 Customer and order-data access 🔹 Same-origin actions using the administrator session 🔹 Order, account or configuration manipulation 🔹 Persistent execution against multiple staff members ⚠️ This is not direct server-side RCE, but abuse of a privileged browser session could lead to shop takeover depending on the administrator’s permissions and available functionality. 🛡 Defenders: ✅ Upgrade to official Phoca Cart 6.1.8 or later now. ✅ Avoid opening suspicious orders in an unpatched backend. ✅ Hunt stored User-Agent values and web/proxy logs for encoded HTML or JavaScript. ✅ Audit Joomla users, ACLs, extensions, templates and configuration changes. ✅ Review custom overrides and exports that render User-Agent metadata. ✅ Verify the running extension carefully—the public 6.1.8 tag contained stale 6.1.7 version text during review. 🔎 No public executable PoC, confirmed active exploitation or CISA KEV listing was identified as of 21 August 2026. EPSS remains pending. 🔗 Full advisory: https://github.com/advisories/GHSA-98mw-pj3j-99v2 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-76564 #CyberForge #CVEOfTheDay #CVE202676564 #PhocaCart #Joomla #StoredXSS #XSS #AppSec #BlueTeam #ThreatHunting #PatchNow

    Post summary

    The advisory announces a high‑severity stored XSS vulnerability in Phoca Cart, supplies patch information and mitigation steps, and confirms no active exploitation or PoC yet.

    0001082
    562 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Joomla ❗ CVE-2026-76564 ❗ CVE-2026-75948 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-joomla-4/ https://t.co/wBnl5FmOcd

    Post summary

    The tweet announces two Joomla CVEs and directs readers to additional information via provided URLs.

    00000206
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-76564 Stored XSS in Phoca Cart Admin Order View via User-Agent Header https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-76564

    Post summary

    The post announces the discovery of a Stored XSS vulnerability (CVE-2026‑76564) in Phoca Cart’s admin order view, but offers no exploit code, patch information, or evidence of active exploitation.

    00000110
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-76564 Joomla Extension - https://phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 https://www.cve.org/CVERecord?id=CVE-2026-76564

    Post summary

    The message announces a stored XSS vulnerability in Phoca Cart’s admin order view triggered by the User-Agent header, affecting versions 5.0.0 through 6.1.7.

    00000677
    58.0K followersView on X

Explore more