Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-76565Medium

Phoca Cart (com_phocacart) 6.1.7 - Unauthenticated Reflected XSS in the product price filter

Phoca Cart echoes the price_from and price_to request parameters straight into the value attribute of the product filter text inputs, in the site layouts form_filter_text.php and form_filter_horizontal_text.php, with no escaping. No login is required: a crafted link to a shop category or product list page whose price_from value contains a double quote breaks out of the attribute and runs attacker script in the browser of anyone who opens it. The filter panel is rendered on the public shop pages whenever the price filter is enabled. 6.1.8 wraps both values in htmlspecialchars with ENT_QUOTES and ENT_SUBSTITUTE, and also escapes an unescaped value in the administrator Phoca Render Adminview helper. Confirmed by diffing the released com_phocacart zips on 2026-08-18. Update to 6.1.8. Note that 6.1.7 was itself the fix for the CVE-2026-74251 product filter SQL injection, so a site on 6.1.7 is exposed to this cross site scripting issue only, not to the SQL injection.

Affected versions: ≥ 6.1.7 and < 6.1.8

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 13 September 2026.