VYPR

J-BusinessDirectory

by Joomla

CVEs (9)

  • CVE-2026-75949CriAug 19, 2026
    risk 0.65cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak…

  • CVE-2026-75954CriAug 19, 2026
    risk 0.60cvss epss 0.00

    Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.

  • CVE-2026-75956HigAug 19, 2026
    risk 0.57cvss epss 0.00

    Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic, and limit was not validated…

  • CVE-2019-25752HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the…

  • CVE-2026-75953HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.

  • CVE-2026-75951MedAug 19, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3

  • CVE-2026-75950MedAug 19, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated…

  • CVE-2026-75955MedAug 19, 2026
    risk 0.33cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.

  • CVE-2026-75952MedAug 19, 2026
    risk 0.30cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install,…