PatchSiren

cmsjunkie.com CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cmsjunkie.com CVE published 2026-08-19

CVE-2026-75956

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:18:10.313Z and has not been modified since then. CVE-2026-75956 is a DOS vulnerability in the Joomla Extension - cmsjunkie.com - J-BusinessDirectory. The vulnerability arises from the lack of strict typing in pagination parameter handling, allowing array or non-numeric values to trigger PHP ty [truncated]

MEDIUM cmsjunkie.com CVE published 2026-08-19

CVE-2026-75955

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:18:10.183Z and has not been modified since then. The Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 vulnerability occurs when the companyName parameter from the request is written unescaped into an XML attribute. This allows attackers to inject [truncated]

CRITICAL cmsjunkie.com CVE published 2026-08-19

CVE-2026-75954

The CVE-2026-75954 record indicates a SQL injection vulnerability in Joomla Extension J-BusinessDirectory version less than 6.2.3. The vulnerability is caused by concatenating search keywords and ORDER BY clauses into SQL. Version 6.2.3 quotes keywords and allow-lists the sort clause, mitigating the issue. This vulnerability has a CVSS score of 9.3 and is considered critical. Administrators and users of J [truncated]

MEDIUM cmsjunkie.com CVE published 2026-08-19

CVE-2026-75951

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T15:18:09.693Z and has not been modified since then. The J-BusinessDirectory extension for Joomla is vulnerable to Insecure Direct Object Reference attacks in multiple frontend/API actions. This vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. Administrators and users of [truncated]

CRITICAL cmsjunkie.com CVE published 2026-08-19

CVE-2026-75949

The Joomla Extension - cmsjunkie.com - J-BusinessDirectory is vulnerable to arbitrary file upload and deletion due to a path traversal issue in versions prior to 6.2.3. This critical vulnerability, with a CVSS score of 10, arises from the component's handling of client-controlled root paths, lack of path containment enforcement, and weak extension checks. A CSRF token is also missing on upload and remove [truncated]