CVE WATCH / VULNERABILITY DETAIL
CVE-2026-102775
UNKNOWNCVSS 0NVD feed
Published 5 October 2026 · tracked since 5 October 2026
Description
Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-empti
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102779
- CVE-2026-102777
- CVE-2026-102282 HIGH 7.1
- CVE-2026-88396
- CVE-2026-88393
- CVE-2026-105329 MEDIUM 6.3
- CVE-2026-105397 MEDIUM 5.4
- CVE-2026-104890 HIGH 7.2
- CVE-2026-102426
- CVE-2026-102428