CVE-2026-76565Disclosure

MEDIUMCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-20); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-20: 3Mentions · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-24: 1Exploit Tool / Code · 2026-08-24: 1Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-20: 3Technical Details · 2026-08-24: 108-2008-24
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-203
Disclosure2General1
2026-08-241
PoC1
Full discourse4 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart GitHub: https://github.com/toanln-cov/CVE-2026-76565 A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla. The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim. The PoC demonstrates: • Reflected XSS through crafted GET parameters • Exploitation of vulnerable price filter inputs • Attribute-context injection caused by missing htmlspecialchars() encoding • No authentication requirement for exploitation • Affected versions: PhocaCart ≤ 6.1.7 • Fixed version: PhocaCart 6.1.8 💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.

    Post summary

    A PoC for CVE-2026-76565, a reflected XSS in PhocaCart, has been published on GitHub, detailing the exploitation method and offering a fixed version.

    0502798.3K
    240.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-76565 Reflected XSS in Joomla Phoca Cart via Price Filter Parameters https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-76565

    Post summary

    The post highlights a reflected XSS vulnerability in Joomla’s Phoca Cart but offers only basic technical details without evidence of exploitation, mitigation, or proof of concept.

    00000105
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-76565 Joomla Extension - https://phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 https://www.cve.org/CVERecord?id=CVE-2026-76565 ----- Traducción: CVE-2026-76565 Extensión de Joomla - … https://infoflow.cloud`

    Post summary

    A reflected XSS vulnerability (CVE‑2026‑76565) in the Phoca Cart Joomla extension, affecting versions 5.0.0 to 6.1.7, has been disclosed with technical details but no PoC, exploit, or patch information.

    0000022
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-76565 Joomla Extension - https://phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 https://www.cve.org/CVERecord?id=CVE-2026-76565

    Post summary

    A reflected XSS vulnerability (CVE-2026-76565) affecting Phoca Cart 5.0.0‑6.1.7 via price_from and price_to parameters has been disclosed.

    00000712
    58.0K followersView on X

Explore more