HIGH
CVE-2026-66491
CVSS
8.2
Description
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
0.38%
Probability of exploitation in next 30 days
31.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.