Joomla 扩展 – cmsjunkie.com – J-BusinessDirectory < 6.2.3 版本存在跨站请求伪造(CSRF)漏洞。 在许多涉及 AJAX 或状态变更的操作中,缺失必要的 CSRF 令牌保护,具体包括:联系/报价表单、购物车、收藏夹(书签)、文件上传、消息处理、AI 文本生成,以及多个后台管理操作(如应用程序安装、示例数据清除、缓存/统计信息归档、支付通知发送、移动推送等)。 前端页面的 CSRF 攻击需要攻击者具备已注册用户或listing所有者的会话;而后台管理页面的 CSRF
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75949 | 10.0 CRITICAL | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J |
| CVE-2026-75954 | 9.3 CRITICAL | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < |
| CVE-2026-75956 | 8.7 HIGH | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-Busine |
| CVE-2026-75951 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/AP |
| CVE-2026-75950 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-Busines |
| CVE-2026-75955 | 5.1 MEDIUM | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < |
| CVE-2026-75953 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 |
No comments yet