Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-75949CriticalCVSS 10.0CVE published 19 August 2026Added to mySites.guru 19 August 2026

J-BusinessDirectory (com_jbusinessdirectory) 4.9.8 to 6.2.2 - Unauthenticated Arbitrary File Upload and Path Traversal (RCE, CVSS 10.0), Unauthenticated SQL Injection and Seven Further Issues

CMSJunkie released J-BusinessDirectory 6.2.3 on 31 July 2026 to fix eight security issues found during their own security review. The technical detail was withheld at the time and was published as CVEs on 19 August 2026, all of them stated as affecting 1.0.0 to 6.2.2. The most serious, CVE-2026-75949 (CVSS 10.0), is an unauthenticated arbitrary file upload and deletion: the upload and remove handlers accepted a client-controlled path root (_path_type could be pointed at the component site or admin trees), enforced no path containment, used a weak file extension check, and carried no CSRF token, which gives an anonymous attacker remote code execution and arbitrary file deletion. CVE-2026-75954 (CVSS 9.3) is an unauthenticated SQL injection in the trips search, where the search keywords and the ORDER BY clause were concatenated into the query. CVE-2026-75956 (CVSS 8.7) is a denial of service through untyped pagination parameters, where an array such as limitstart[] triggers PHP type errors and limit was never validated. CVE-2026-75950 and CVE-2026-75951 (both CVSS 6.9) are an unauthenticated listing ownership takeover using attacker-supplied company and user IDs, including for listings that already had an owner, and insecure direct object references across multiple front-end and API actions. CVE-2026-75955 (CVSS 5.1) is a reflected XSS and XML injection via an unescaped companyName written into an XML attribute. CVE-2026-75952 (CVSS 4.6) is missing CSRF tokens on many state-changing tasks: contact and quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions. CVE-2026-75953 is an open mail relay, taking the recipient address from the request (contact_id_offer / contact_id_event) rather than the stored offer or event record. Also inside this range is CVE-2020-5182, reverse tabnabbing on the user-supplied business website link, fixed in 5.2.9. Update to 6.2.5 or later rather than stopping at 6.2.3: CMSJunkie shipped two further security releases (6.2.4 on 7 August and 6.2.5 on 14 August 2026), so 6.2.3 and 6.2.4 are still flagged. The JBD Apps add-ons must be updated to their own latest versions as well. Until you can update, treat the site as exposed to unauthenticated remote code execution: restrict front-end access to the directory and review the site for unexpected users, listings and PHP files under the component media and upload folders.

Is my site affected?

CVE-2026-75949 is checked by 2 rules. Find the extension and release line your site runs:

ExtensionAffected versionsFixed inWhat to do
J-BusinessDirectoryafter 4.9.7 up to but not including 6.2.36.2.3Update J-BusinessDirectory to 6.2.3 for this flaw, or to 6.2.5 or later, which no rule we check matches.
J-BusinessDirectoryup to and including 4.9.7update to 6.2.5Update J-BusinessDirectory to 6.2.5 or later.

How CVE-2026-75949 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

10.0 Critical

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:H Confidentiality
High. Everything the site holds can be read
VI:H Integrity
High. Data and files can be altered at will
VA:H Availability
High. The site can be taken down

What it does beyond the site

SC:H Confidentiality
High. Data on other systems can be read
SI:H Integrity
High. Other systems can be altered
SA:H Availability
High. Other systems can be taken down

Timeline

  1. 1 January 2019mySites.guru check added for J-BusinessDirectory (up to and including 4.9.7)
  2. 19 August 2026CVE-2026-75949 record published by its CNA
  3. 19 August 2026mySites.guru check added for J-BusinessDirectory (after 4.9.7 up to but not including 6.2.3)

Rule details

J-BusinessDirectory - J-BusinessDirectory (com_jbusinessdirectory) 4.9.7 and below - Unauthenticated Arbitrary File Upload and Path Traversal (RCE, CVSS 10.0), Multiple Unauthenticated SQL Injections and Six Further Issues

J-BusinessDirectory 4.9.7 and every earlier release are affected by an unauthenticated SQL injection via the type parameter (index.php?option=com_jbusinessdirectory&task=categories.getCategories), CVE-2019-25752. These versions also sit inside the range CMSJunkie fixed in 6.2.3, published as eight further CVEs on 19 August 2026 and all stated as affecting 1.0.0 to 6.2.2. The most serious of those is CVE-2026-75949 (CVSS 10.0), an unauthenticated arbitrary file upload and deletion: the upload and remove handlers accepted a client-controlled path root (_path_type could be pointed at the component site or admin trees), enforced no path containment, used a weak file extension check, and carried no CSRF token, which gives an anonymous attacker remote code execution and arbitrary file deletion. The rest are CVE-2026-75954 (CVSS 9.3, unauthenticated SQL injection in the trips search), CVE-2026-75956 (CVSS 8.7, denial of service via untyped pagination parameters such as limitstart[]), CVE-2026-75950 and CVE-2026-75951 (both CVSS 6.9, unauthenticated listing ownership takeover and insecure direct object references across multiple front-end and API actions), CVE-2026-75955 (CVSS 5.1, reflected XSS and XML injection via an unescaped companyName), CVE-2026-75952 (CVSS 4.6, missing CSRF tokens on many state-changing tasks) and CVE-2026-75953 (open mail relay taking the recipient address from the request). A release this old is several years behind and has no partial fix available: update to 6.2.5 or later, update the JBD Apps add-ons to their own latest versions, and until you do, treat the site as exposed to unauthenticated remote code execution and review it for unexpected users, listings and PHP files under the component media and upload folders.

Affected versions: ≤ 4.9.7

Full advisory: nvd.nist.gov

Other vulnerabilities in J-BusinessDirectory

Updating for CVE-2026-75949 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

J-BusinessDirectory

Latest safe version: 6.2.5

All 10 CVEs in J-BusinessDirectory

References

CVE-2026-75949 questions

Which versions are affected by CVE-2026-75949?
CVE-2026-75949 is covered by 2 rules: J-BusinessDirectory after 4.9.7 up to but not including 6.2.3; J-BusinessDirectory up to and including 4.9.7.
How do I fix CVE-2026-75949?
It depends on the extension and release line your site runs. For J-BusinessDirectory after 4.9.7 up to but not including 6.2.3: update J-BusinessDirectory to 6.2.3 for this flaw, or to 6.2.5 or later, which no rule we check matches. For J-BusinessDirectory up to and including 4.9.7: update J-BusinessDirectory to 6.2.5 or later.
How severe is CVE-2026-75949?
Joomla CNA scores it 10.0 (Critical) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.