CVE-2026-75952
- EPSS 0.16%
- Veröffentlicht 19.08.2026 14:46:52
- Zuletzt bearbeitet 20.08.2026 16:18:06
Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administra...
- EPSS 0.15%
- Veröffentlicht 19.08.2026 14:45:26
- Zuletzt bearbeitet 19.08.2026 15:18:09
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitra...
CVE-2026-75955
- EPSS 0.32%
- Veröffentlicht 19.08.2026 14:45:23
- Zuletzt bearbeitet 19.08.2026 15:18:10
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.
CVE-2026-75951
- EPSS 0.3%
- Veröffentlicht 19.08.2026 14:41:50
- Zuletzt bearbeitet 19.08.2026 15:18:09
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
CVE-2026-75956
- EPSS 0.31%
- Veröffentlicht 19.08.2026 14:41:30
- Zuletzt bearbeitet 19.08.2026 15:18:10
Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic...
CVE-2026-75954
- EPSS 0.28%
- Veröffentlicht 19.08.2026 14:41:04
- Zuletzt bearbeitet 19.08.2026 15:18:10
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.
- EPSS 0.31%
- Veröffentlicht 19.08.2026 14:40:42
- Zuletzt bearbeitet 19.08.2026 15:18:09
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path co...
CVE-2026-75950
- EPSS 0.3%
- Veröffentlicht 19.08.2026 14:40:08
- Zuletzt bearbeitet 19.08.2026 15:18:09
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the ...
CVE-2019-25752
- EPSS 0.45%
- Veröffentlicht 19.06.2026 17:15:06
- Zuletzt bearbeitet 19.08.2026 17:59:33
Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to inde...
CVE-2020-5182
- EPSS 1.05%
- Veröffentlicht 03.02.2020 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:33:38
The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as noreferrer)...