Phoca and Joomla 3
Has published nothing about Joomla 3. Phoca Cart 3.5.8, from October 2021, is still the newest release offered to Joomla 3 sites, and the 2026 Phoca Cart security releases have no Joomla 3 version.
Joomla extensions covered: Phoca Cart, Phoca Download, Phoca Commander, Phoca Gallery. Phoca website
What they said
Phoca has no public statement on Joomla 3 that we could find. Most vendors never say, so what they ship is the only evidence.
Known Joomla 3 vulnerabilities
- High
Phoca Cart (com_phocacart) below 6.1.9 - Unauthenticated Order Download IDOR (paid file disclosure)
Affected: ≥ 3.0.0 and < 6.1.9
- Critical
Phoca Cart (com_phocacart) 3.x - Unauthenticated SQL Injection in the product filter, no fixed release (CVE-2026-74251)
Affected: ≥ 3.0.0 and < 4.0.0
- Critical
Phoca Download (com_phocadownload) 3.x and earlier - Authenticated Arbitrary File Upload (RCE), no fixed release for Joomla 3 (CVE-2026-57828, CVSS 9.0 Critical)
Affected: < 4.0.0
- High
Phoca Commander (com_phocacommander) below 6.1.2 - Authenticated Arbitrary File Write (RCE), Arbitrary File Read and Reflected XSS
Affected: < 6.1.2
- Unrated
Phoca Commander (com_phocacommander) 6.1.2 to 6.1.3 - Authenticated Path Traversal: Arbitrary File Read, Upload, Delete, Copy and Move (CVE-2026-66491, CVE-2026-66492, CVE-2026-66493)
Affected: ≥ 6.1.2 and < 6.1.4
Our coverage
- Phoca Cart 6.1.9 stops anyone downloading other customers' paid files
Phoca Cart before 6.1.9 let anonymous visitors download the digital products other customers bought. Only the Joomla 6 line is fixed, and 6.1.8 is affected.
- Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection
Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.
See which of your sites run Phoca Cart
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Is a Joomla 3 site hacked right now?
We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.