Phoca Maps (com_phocamaps) <= 6.0.9 - Unauthenticated Reflected XSS (CVE-2026-65763)
Phoca Maps by phoca.cz is affected by a reflected cross-site scripting vulnerability (CVE-2026-65763): improper validation of user input reflects attacker-controlled script. Affects all versions 1.0.0 through 6.0.9; fixed in 6.1.0. Complements the existing Phoca Maps stored-XSS rule (CVE-2026-23900, 5.0.0 to below 6.0.3) by extending coverage up to 6.0.9 and to older releases.
Affected versions: ≤ 6.0.9
Full advisory: nvd.nist.gov