CVE-2026-102775

CVE-2026-102775 published: Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order ...

View full NVD advisory → ← Back to CVE watch