Affected versions: ≤ 4.9.7
Full advisory: nvd.nist.gov
Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE
J-BusinessDirectory 4.9.7 and every earlier release are affected by an unauthenticated SQL injection via the type parameter (index.php?option=com_jbusinessdirectory&task=categories.getCategories), CVE-2019-25752. These versions also sit inside the range CMSJunkie fixed in 6.2.3, published as eight further CVEs on 19 August 2026 and all stated as affecting 1.0.0 to 6.2.2. The most serious of those is CVE-2026-75949 (CVSS 10.0), an unauthenticated arbitrary file upload and deletion: the upload and remove handlers accepted a client-controlled path root (_path_type could be pointed at the component site or admin trees), enforced no path containment, used a weak file extension check, and carried no CSRF token, which gives an anonymous attacker remote code execution and arbitrary file deletion. The rest are CVE-2026-75954 (CVSS 9.3, unauthenticated SQL injection in the trips search), CVE-2026-75956 (CVSS 8.7, denial of service via untyped pagination parameters such as limitstart[]), CVE-2026-75950 and CVE-2026-75951 (both CVSS 6.9, unauthenticated listing ownership takeover and insecure direct object references across multiple front-end and API actions), CVE-2026-75955 (CVSS 5.1, reflected XSS and XML injection via an unescaped companyName), CVE-2026-75952 (CVSS 4.6, missing CSRF tokens on many state-changing tasks) and CVE-2026-75953 (open mail relay taking the recipient address from the request). A release this old is several years behind and has no partial fix available: update to 6.2.5 or later, update the JBD Apps add-ons to their own latest versions, and until you do, treat the site as exposed to unauthenticated remote code execution and review it for unexpected users, listings and PHP files under the component media and upload folders.
Affected versions: ≤ 4.9.7
Official record: cve.org · NVD
Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.
Affected versions: ≤ 4.9.7
Full advisory: nvd.nist.gov
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 25 August 2026.