PULSE
LIVE55signals / 24h
FEED
ransomspacebears reclama a Hitech Distribuzione Informatica S.r.l. (HTDI) · IT · Technologyransomstorm reclama a Pioneer Bank · US · Financial Servicesransomthegentlemen reclama a Hartfiel Automation · DE · Manufacturingransomqilin reclama a Astro Electroplating · US · Manufacturingransomqilin reclama a Filtronic · GB · Manufacturingransomqilin reclama a EISNER ZT GMBH · AT · Professional Servicesransomqilin reclama a John C Saunders, CPA · US · Professional Servicesransomqilin reclama a Nikan Awasisak Agency · CA · Not Foundransomqilin reclama a Depona · SE · Technologyransomclop reclama a CONTINENTAL.AERO · US · Transportationransomclop reclama a MINDRAY.COM · CN · Healthcareransomincransom reclama a ATMS · IN · Transportationransomthegentlemen reclama a DHC · JP · Not Foundransomthegentlemen reclama a INKA Group GmbH Co · DE · Manufacturingransomspacebears reclama a Hitech Distribuzione Informatica S.r.l. (HTDI) · IT · Technologyransomstorm reclama a Pioneer Bank · US · Financial Servicesransomthegentlemen reclama a Hartfiel Automation · DE · Manufacturingransomqilin reclama a Astro Electroplating · US · Manufacturingransomqilin reclama a Filtronic · GB · Manufacturingransomqilin reclama a EISNER ZT GMBH · AT · Professional Servicesransomqilin reclama a John C Saunders, CPA · US · Professional Servicesransomqilin reclama a Nikan Awasisak Agency · CA · Not Foundransomqilin reclama a Depona · SE · Technologyransomclop reclama a CONTINENTAL.AERO · US · Transportationransomclop reclama a MINDRAY.COM · CN · Healthcareransomincransom reclama a ATMS · IN · Transportationransomthegentlemen reclama a DHC · JP · Not Foundransomthegentlemen reclama a INKA Group GmbH Co · DE · Manufacturing
← All CVEs
CVE WatchAug 7, 2026

CVE-2026-66491

Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function le

CVSS

No CVSS

EPSS

KEV

Exploit Today

0

0-100

Published: Aug 7, 2026 · Last modified: Aug 7, 2026 · CWE-22

EPSS · 30d

Not enough EPSS history yet.

Technical description

Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-66493
0Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.8h
CVE-2026-66492
0Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.8h
CVE-2026-491638.8 HIG
0Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.17h
CVE-2026-71476
0Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious or on-path (MITM) remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on the machine running Nx, which can be escalated to remote code execution. Nx's default local cache and Nx Cloud are not affected; only workspaces configured to use a self-hosted remote cache are affected. This issue is fixed in versions 22.7.7 and 23.0.2.19h
CVE-2026-64677
0Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.19h
CVE-2026-64653
0GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource values to make gh address a different API endpoint or resource than the user intended. This issue is fixed in version 2.97.0.19h