Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-75949: J-BusinessDirectory Joomla Extension: Unsecured File Upload/Deletion

CVE-2026-75949 · published 4 days ago
Summary

An unsecured Joomla extension called J-BusinessDirectory allows attackers to upload or delete any file on the server. This is a serious issue because it could allow an attacker to harm the website or steal sensitive data. To protect your site, update J-BusinessDirectory to version 6.2.3 or later.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cmsjunkie.com j-businessdirectory extension for joomla 1.0.0-6.2.2
Original advisory text
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.
Severity
10.0 Critical
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published19 Aug 2026
Updated22 Aug 2026
First seen19 Aug 2026
Sources
CVE-2026-75949 · MITRE
Monitor software like this
Free during beta