Phoca Commander Remote Code Execution Vulnerability for Joomla
Vulnerability
A remote code execution vulnerability has been identified in the Phoca Commander component for Joomla, affecting versions 1.0.0 through 4.0.0 and 5.0.0 through 5.0.1. The vulnerability arises from the unzip feature, which can be exploited to execute arbitrary code.
Impact
Exploitation of this vulnerability allows authenticated users to execute arbitrary code on the server where Joomla is hosted.
Added: Aug 15, 2025, 12:20 PM
Updated: Aug 15, 2025, 1:17 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
5.2remediation
7.7relevance
0.3threat
0.0urgency
0.0incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
