VYPR

J-BusinessDirectory

by Cmsjunkie.com

CVEs (4)

  • CVE-2026-75949CriAug 19, 2026
    risk 0.65cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak…

  • CVE-2026-75954CriAug 19, 2026
    risk 0.60cvss epss 0.00

    Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.

  • CVE-2026-75951MedAug 19, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3

  • CVE-2026-75950MedAug 19, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated…