
‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart GitHub: https://github.com/toanln-cov/CVE-2026-76565 A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≤ 6.1.7 for Joomla. The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim. The PoC demonstrates: • Reflected XSS through crafted GET parameters • Exploitation of vulnerable price filter inputs • Attribute-context injection caused by missing htmlspecialchars() encoding • No authentication requirement for exploitation • Affected versions: PhocaCart ≤ 6.1.7 • Fixed version: PhocaCart 6.1.8 💥 No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
Post summary
A PoC for CVE-2026-76565, a reflected XSS in PhocaCart, has been published on GitHub, detailing the exploitation method and offering a fixed version.



