Joomla 扩展:cmsjunkie.com 的 J-BusinessDirectory 版本低于 6.2.3 中存在反射型跨站脚本漏洞(Reflected XSS)和 XML 注入漏洞。请求中的 参数未经过转义处理,直接被写入到 XML 属性中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cmsjunkie.com | J-BusinessDirectory extension for Joomla | 1.0.0-6.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75949 | 10.0 CRITICAL | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J |
| CVE-2026-75954 | 9.3 CRITICAL | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < |
| CVE-2026-75956 | 8.7 HIGH | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-Busine |
| CVE-2026-75951 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/AP |
| CVE-2026-75950 | 6.9 MEDIUM | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-Busines |
| CVE-2026-75952 | 4.6 MEDIUM | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6. |
| CVE-2026-75953 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 |
No comments yet