CVE-2026-76564
Received Received - Intake

Stored XSS in Phoca Cart Admin Order View via User-Agent

Vulnerability report for CVE-2026-76564, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: Joomla! Project

Description

Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
phoca phoca_cart 5.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in Phoca Cart 5.0.0-6.1.7, a Joomla e-commerce extension. It allows attackers to inject malicious scripts via the User-Agent header, which are then stored and executed when viewed in the Admin Order View.

Detection Guidance

To detect this Stored XSS vulnerability in Phoca Cart, monitor HTTP request logs for unusual User-Agent headers containing script tags. Check Joomla admin order views for unexpected JavaScript execution. Use WAF logs to identify suspicious input patterns in User-Agent fields targeting Phoca Cart components.

Impact Analysis

An attacker could steal session cookies, perform actions on your behalf, or deface your Joomla admin interface. This could lead to unauthorized access, data theft, or complete compromise of your online store.

Compliance Impact

This vulnerability could lead to unauthorized access to customer data, violating GDPR's data protection requirements. For HIPAA, it may expose protected health information if the store handles such data, risking compliance violations.

Mitigation Strategies

Immediately update Phoca Cart to the latest version beyond 6.1.7. Implement input validation to sanitize User-Agent headers in Joomla. Deploy a web application firewall to block XSS payloads. Monitor admin order views for unauthorized script execution and restrict admin access to trusted IPs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76564. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart