Skip to main content

Phoca and Joomla 3

No public statement

Has published nothing about Joomla 3. Phoca Cart 3.5.8, from October 2021, is still the newest release offered to Joomla 3 sites, and the 2026 Phoca Cart security releases have no Joomla 3 version.

Joomla extensions covered: Phoca Cart, Phoca Download, Phoca Commander, Phoca Gallery. Phoca website

What they said

Phoca has no public statement on Joomla 3 that we could find. Most vendors never say, so what they ship is the only evidence.

What they did

  1. Phoca Cart 3.5.8, still the newest release offered to Joomla 3 sites

    Source

  2. Phoca Cart 6.1.7 security release; the Joomla 3 line stays on 3.5.8 with no fix

    Source

  3. Phoca Cart 6.1.9 security release; 3.5.8 for Joomla 3 has the same flaw and no fixed release

    Source

Known Joomla 3 vulnerabilities

  • High

    Phoca Cart (com_phocacart) below 6.1.9 - Unauthenticated Order Download IDOR (paid file disclosure)

    Affected: ≥ 3.0.0 and < 6.1.9

  • Critical

    Phoca Cart (com_phocacart) 3.x - Unauthenticated SQL Injection in the product filter, no fixed release (CVE-2026-74251)

    Affected: ≥ 3.0.0 and < 4.0.0

    CVE-2026-74251

  • Critical

    Phoca Download (com_phocadownload) 3.x and earlier - Authenticated Arbitrary File Upload (RCE), no fixed release for Joomla 3 (CVE-2026-57828, CVSS 9.0 Critical)

    Affected: < 4.0.0

    CVE-2026-57828

  • High

    Phoca Commander (com_phocacommander) below 6.1.2 - Authenticated Arbitrary File Write (RCE), Arbitrary File Read and Reflected XSS

    Affected: < 6.1.2

    CVE-2026-65764, CVE-2026-65765, CVE-2025-54473

  • Unrated

    Phoca Commander (com_phocacommander) 6.1.2 to 6.1.3 - Authenticated Path Traversal: Arbitrary File Read, Upload, Delete, Copy and Move (CVE-2026-66491, CVE-2026-66492, CVE-2026-66493)

    Affected: ≥ 6.1.2 and < 6.1.4

    CVE-2026-66491, CVE-2026-66492, CVE-2026-66493

Our coverage

See which of your sites run Phoca Cart

Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.

Is a Joomla 3 site hacked right now?

We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.

Audit a Joomla 3 site free