PatchSiren cyber security CVE debrief
CVE-2026-75955 cmsjunkie.com CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:18:10.183Z and has not been modified since then. The Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 vulnerability occurs when the companyName parameter from the request is written unescaped into an XML attribute. This allows attackers to inject malicious XML and execute JavaScript code. The vulnerability has a CVSS score of 5.1 and a severity rating of MEDIUM. Affected systems should be reviewed and patched to prevent exploitation. Administrators and users of Joomla installations with the J-BusinessDirectory extension should review and apply patches to prevent exploitation of this vulnerability. Additionally, security teams and vulnerability management teams should be aware of the potential risks associated with this vulnerability and take steps to mitigate them. This includes reviewing system configurations, monitoring for suspicious activity, and implementing compensating controls as necessary.
- Vendor
- cmsjunkie.com
- Product
- J-BusinessDirectory extension for Joomla
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Administrators and users of Joomla installations with the J-BusinessDirectory extension should review and apply patches to prevent exploitation of this vulnerability. Additionally, security teams and vulnerability management teams should be aware of the potential risks associated with this vulnerability and take steps to mitigate them. This includes reviewing system configurations, monitoring for suspicious activity, and implementing compensating controls as necessary.
Technical summary
The Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 vulnerability occurs when the companyName parameter from the request is written unescaped into an XML attribute. This allows attackers to inject malicious XML and execute JavaScript code. The vulnerability has a CVSS score of 5.1 and a severity rating of MEDIUM. Affected systems should be reviewed and patched to prevent exploitation.
Defensive priority
Medium-priority defensive review recommended due to reflected XSS / XML injection in J-BusinessDirectory.
Recommended defensive actions
- Review and apply vendor patches for J-BusinessDirectory
- Implement input validation and output encoding for companyName parameter
- Monitor for suspicious activity related to XML injection and XSS
- Consider compensating controls such as web application firewalls
- Review system logs for potential exploitation attempts
Evidence notes
Evidence from official CVE and NVD sources indicates a reflected XSS / XML injection vulnerability in J-BusinessDirectory. The companyName parameter from the request was written unescaped into an XML attribute. Limited additional context available. Further review of J-BusinessDirectory configurations and deployment scenarios may be necessary to fully understand potential exposure. Additional verification tasks may include reviewing system logs for suspicious activity and ensuring that input validation and output encoding are properly implemented.
Official resources
-
CVE-2026-75955 CVE record
CVE.org
-
CVE-2026-75955 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:18:10.183Z and has not been modified since then.