Cmsjunkie
Cmsjunkie J-businessdirectory: vulnerabilities and CVEs
Cmsjunkie J-businessdirectory has 7 published vulnerabilities, 6 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months6
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-75955 | Medium (5.1) | 0.44% | — | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute. |
| CVE-2026-75954 | Critical (9.3) | 0.39% | — | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause. |
| CVE-2026-75953 | High (7.5) | 0.42% | — | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so… |
| CVE-2026-75950 | Medium (6.9) | 0.41% | — | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already… |
| CVE-2026-75949 | Critical (10) | 0.43% | — | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin… |
| CVE-2019-25752 | High (8.8) | 0.49% | — | Jun 19, 2026 | Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter.… |
| CVE-2020-5182 | Medium (6.5) | 1.0% | — | Feb 3, 2020 | The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.