A vulnerability marked as critical has been reported in phoca.cz Phoca Cart Extension up to 6.1.16. This affects an unknown function. The manipulation of the argument a/s leads to sql injection.

This vulnerability is uniquely identified as CVE-2026-74251. The attack is possible to be carried out remotely. No exploit exists.