PT-2026-32097 · Unknown · Phoca Maps

Felipe Monteiro

+1

·

Published

2026-04-11

·

Updated

2026-04-11

·

CVE-2026-23900

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Phoca Maps versions 5.0.0 through 6.0.2
Description The Phoca Maps component contains stored cross-site scripting (XSS) vulnerabilities in the maps and icon rendering logic. These flaws could allow an attacker to inject malicious scripts into web pages viewed by other users.
Recommendations Update Phoca Maps to a version later than 6.0.2.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-23900

Affected Products

Phoca Maps