Phoca Cart 6.1.9 addresses a paid-download insecure direct object reference (IDOR) issue that Joomla shop owners should remediate promptly, particularly where digital products are sold. The update is distinct from two earlier, CVE-tracked cross-site scripting flaws fixed in version 6.1.8, so administrators need to understand which release resolves which issue.
Phoca Cart shops that provide paid digital downloads should review their installed version and plan an upgrade to 6.1.9 or a later applicable release. The paid-download IDOR addressed in 6.1.9 is separate from the two documented Phoca Cart XSS vulnerabilities fixed in 6.1.8; treating all three issues as one vulnerability would lead to incorrect risk reporting and incomplete remediation.
What Phoca Cart 6.1.9 addresses
Phoca Cart 6.1.9 addresses an issue described as an insecure direct object reference, or IDOR, in the paid-download area. In general, an IDOR occurs when an application does not adequately verify that the current user is authorised to access a specific object or resource. For an ecommerce extension, access-control checks around paid digital goods are particularly important because they help ensure that download access remains tied to the appropriate order or entitlement.
The available publisher analysis identifies the paid-download issue as fixed in version 6.1.9. This is a practical update priority for sites that use Phoca Cart to sell downloadable products. However, the available evidence does not assign this issue a CVE identifier, an official CVSS score, or an official severity rating. It should therefore be discussed as a separate, vendor-reported security fix rather than being labelled with the identifiers or scores of other Phoca Cart vulnerabilities.
There is also no authoritative evidence in the available records that this IDOR has been exploited in the wild or linked to ransomware activity. Site owners do not need confirmed exploitation to act: protecting customer entitlements and paid content is sufficient reason to deploy the available fix through a controlled maintenance process.
Known Phoca Cart XSS vulnerabilities are separate
Two earlier Phoca Cart vulnerabilities have verified CVE records. Both affect versions 5.0.0 through 6.1.7 and were fixed in Phoca Cart 6.1.8. They are not identifiers for the paid-download IDOR fixed in 6.1.9.
CVE-2026-76564 is a stored cross-site scripting vulnerability involving attacker-controlled User-Agent data that may later be rendered in the administrator order view. An attacker who successfully causes this content to be processed could run JavaScript in an administrator's browser session. CVE-2026-76565 is a reflected cross-site scripting vulnerability involving the price_from and price_to filter parameters. It could be triggered if a user visits a crafted shop link.
| Extension | CVE | Issue | Authentication | Affected versions | Recommended version | CVSS 4.0 | CISA KEV status |
|---|---|---|---|---|---|---|---|
| Phoca Cart | CVE-2026-76564 | Stored XSS through User-Agent data in the administrator order view | Required | 5.0.0 through 6.1.7 | 6.1.8 or later | 8.6 — High | Not listed in the available CISA KEV results |
| Phoca Cart | CVE-2026-76565 | Reflected XSS through price filter parameters | Not required | 5.0.0 through 6.1.7 | 6.1.8 or later | 5.3 — Medium | Not listed in the available CISA KEV results |
The CVSS 4.0 score of 8.6 applies only to CVE-2026-76564, and the CVSS 4.0 score of 5.3 applies only to CVE-2026-76565. Neither score measures the paid-download IDOR. CVSS is a severity model for a specific vulnerability; it is not proof that exploitation has occurred.
The National Vulnerability Database entries for both XSS CVEs currently have a status of Deferred. Administrators can use the CVE records and the vendor's release information for the currently available details, while recognising that NVD analysis may evolve. The deferred status should not be represented as a completed NVD assessment.
Why the distinction matters for Joomla extension vulnerabilities
Accurate separation of issues is an essential part of managing Joomla extension vulnerabilities. An upgrade from an affected 5.0.0–6.1.7 installation to 6.1.8 addresses the two known XSS vulnerabilities. A site selling paid downloads should then ensure it is on 6.1.9 or a later applicable release to include the separate paid-download IDOR fix.
This distinction affects both operational decisions and incident communication. Reporting the IDOR as CVE-2026-76564 or CVE-2026-76565 would incorrectly describe its technical category. Applying the XSS CVSS scores to the IDOR would likewise give a risk rating that has not been assigned by CVE or NVD records. A useful security register should record the issues separately:
- CVE-2026-76564: stored XSS, affecting Phoca Cart 5.0.0–6.1.7; fixed in 6.1.8.
- CVE-2026-76565: reflected XSS, affecting Phoca Cart 5.0.0–6.1.7; fixed in 6.1.8.
- Paid-download IDOR: a separate access-control issue reported as fixed in 6.1.9; no CVE ID or official CVSS score is present in the available CVE or NVD records.
For agencies, this also means checking every managed site individually. A catalogue site that does not sell downloads may still need the 6.1.8 XSS remediation. A shop with paid digital products should treat the move to 6.1.9 or later as the complete path identified by the available release information.
Prioritised upgrade steps for Phoca Cart sites
Use a repeatable maintenance process rather than updating a live store without preparation. The objective is to install the relevant security fixes while preserving product data, payment settings, order processing and customer download access.
- Inventory Phoca Cart installations. Identify every Joomla site that has Phoca Cart installed, record its installed version, and note whether it offers paid downloads. Check staging, regional stores and older client sites as well as the primary production store.
- Classify the version risk. Versions 5.0.0 through 6.1.7 are within the verified affected range for both XSS CVEs. Any site selling paid downloads should additionally be reviewed against the 6.1.9 IDOR fix.
- Back up before changing the extension. Take and verify a restorable backup of the Joomla files and database. For a commercial shop, include a rollback plan and select a maintenance window that avoids disrupting order fulfilment.
- Upgrade to the correct target release. Move to at least 6.1.8 to remediate CVE-2026-76564 and CVE-2026-76565. For paid-download sites, move to 6.1.9 or later on the appropriate maintained branch to include the separate IDOR fix. Obtain the extension and follow installation guidance from the Phoca Cart project page.
- Plan for manual installation where necessary. Publisher observations indicate that some Joomla 5 sites may not be offered version 6.1.9 through the automatic updater. Where that occurs, schedule a careful manual extension upgrade from the official package rather than assuming the site is fully patched because no in-dashboard update is shown.
- Test the business-critical workflow. In a safe test environment where possible, validate product display, cart activity, checkout, successful payment handling, order confirmation and authorised paid-download delivery. Confirm that existing entitled customers can still receive their legitimate downloads.
- Record the result. Update the site's maintenance record with the old version, installed version, date, tested workflows and any follow-up work. This is especially useful for freelancers and agencies responsible for multiple Joomla stores.
If a production upgrade must be delayed, reduce exposure operationally: restrict administrative backend access to authorised staff, use separate administrator accounts, minimise privileged access, and closely control who can manage orders and download-related settings. These measures are sensible defence in depth, but they do not replace installation of the relevant fixes.
Post-upgrade checks and administrator hardening
An extension version number alone is not a complete verification method. After updating, confirm that the Joomla administrator interface reports the intended Phoca Cart release and that the update completed without installation errors. Review the extension's configuration and make sure payment, order and download settings have not changed unexpectedly during maintenance.
For the stored XSS issue, administrator access is a particularly important security boundary because the affected display location is an order-management view. Limit backend permissions to users who need them, remove dormant administrator accounts, use strong unique credentials, and enforce the strongest authentication controls available in the site's operating environment. Avoid shared administrator accounts because they make accountability and response more difficult.
For the reflected XSS issue, train staff to treat unusual URLs and unsolicited shop links cautiously. This is a useful general practice, but the primary remediation remains upgrading from the affected 5.0.0–6.1.7 range. Modern browsers and a carefully deployed content security policy can provide additional layers of protection; neither should be relied on as a substitute for the fix.
After an upgrade, monitor normal store activity for unexpected customer support reports involving download access, checkout failures or missing order information. Investigate anomalies with a focus on restoring service and preserving evidence, but do not attempt to recreate suspected vulnerabilities against a live site. If there is reason to believe an account or order process has been affected, follow the organisation's incident-response procedure, review privileged account activity and consider appropriate customer communication.
Monitoring the IDOR and CVE records
The current evidence supports a clear but limited conclusion: Phoca Cart 6.1.9 fixes a paid-download IDOR described by publisher analysis, while the existing CVE records cover earlier XSS issues fixed in 6.1.8. Because the IDOR does not currently have a CVE entry in the available records, its tracking status may change if a future advisory or CVE assignment is published.
Monitor the official Phoca Cart information page for release and installation guidance, and retain links to the two CVE records in the site's vulnerability register. The NVD entry for CVE-2026-76564 and the NVD entry for CVE-2026-76565 are currently marked Deferred, so their details should be revisited when NVD analysis is updated.
The two XSS CVEs are not in the available CISA Known Exploited Vulnerabilities results, and no confirmed exploitation is established by the records reviewed here. That absence should not be interpreted as a reason to postpone updates. For a Joomla ecommerce site, disciplined extension maintenance, restricted administrator access and verification of paid-download workflows are the appropriate response.
Add comment