« Back to list

Cmsjunkie

Cmsjunkie J-businessdirectory: vulnerabilities and CVEs

Cmsjunkie J-businessdirectory has 7 published vulnerabilities, 6 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months6
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-75955Medium (5.1)0.44%—Aug 19, 2026
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.
CVE-2026-75954Critical (9.3)0.39%—Aug 19, 2026
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.
CVE-2026-75953High (7.5)0.42%—Aug 19, 2026
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so…
CVE-2026-75950Medium (6.9)0.41%—Aug 19, 2026
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already…
CVE-2026-75949Critical (10)0.43%—Aug 19, 2026
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin…
CVE-2019-25752High (8.8)0.49%—Jun 19, 2026
Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter.…
CVE-2020-5182Medium (6.5)1.0%—Feb 3, 2020
The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application4
  2. T1005 Data from Local System2
  3. T1505.003 Web Shell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Cmsjunkie