A vulnerability categorized as problematic has been discovered in phoca.cz Phoca Commander Extension up to 5.0.0/6.1.1. This issue affects some unknown processing. Executing a manipulation can lead to cross site scripting.

This vulnerability appears as CVE-2026-65764. The attack may be performed from remote. There is no available exploit.