Vulnerability Bulletins

CVE-2026-66491

   
Affected software JOOMLA
 
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-66491