Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.44% | — | JoomlaAICmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Cmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause. | |
| Aplazada | Alta (7.5) | 0.42% | — | Cmsjunkie J-businessdirectoryAIJoomlaAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address. | |
| Aplazada | Media (6.9) | 0.41% | — | Cmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings. | |
| Aplazada | Crítica (10) | 0.43% | — | JoomlaAICmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also… | |
| Analizada | Alta (8.8) | 0.49% | — | Cmsjunkie J-businessdirectory | 19/6/2026 | 19/8/2026 | Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the… | |
| Modificada | Media (6.5) | 1.0% | — | Cmsjunkie J-businessdirectory | 3/2/2020 | 17/6/2026 | The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as noreferrer), the tabnabbing may occur. To reproduce the bug, create a business… |