Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-75949: J-BusinessDirectory Joomla Extension: Unsecured File Upload/Deletion
CVE-2026-75949 · published 4 days ago
Summary
An unsecured Joomla extension called J-BusinessDirectory allows attackers to upload or delete any file on the server. This is a serious issue because it could allow an attacker to harm the website or steal sensitive data. To protect your site, update J-BusinessDirectory to version 6.2.3 or later.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cmsjunkie.com | j-businessdirectory extension for joomla | 1.0.0-6.2.2 |
Original advisory text
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.
References
Severity
10.0
Critical
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published19 Aug 2026
Updated22 Aug 2026
First seen19 Aug 2026
Monitor software like this
Free during beta