Affected versions: > 4.9.7 and < 6.2.3
Full advisory: www.cmsjunkie.com
Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE
CMSJunkie released J-BusinessDirectory 6.2.3 on 31 July 2026 to fix eight security issues found during their own security review. The technical detail was withheld at the time and was published as CVEs on 19 August 2026, all of them stated as affecting 1.0.0 to 6.2.2. The most serious, CVE-2026-75949 (CVSS 10.0), is an unauthenticated arbitrary file upload and deletion: the upload and remove handlers accepted a client-controlled path root (_path_type could be pointed at the component site or admin trees), enforced no path containment, used a weak file extension check, and carried no CSRF token, which gives an anonymous attacker remote code execution and arbitrary file deletion. CVE-2026-75954 (CVSS 9.3) is an unauthenticated SQL injection in the trips search, where the search keywords and the ORDER BY clause were concatenated into the query. CVE-2026-75956 (CVSS 8.7) is a denial of service through untyped pagination parameters, where an array such as limitstart[] triggers PHP type errors and limit was never validated. CVE-2026-75950 and CVE-2026-75951 (both CVSS 6.9) are an unauthenticated listing ownership takeover using attacker-supplied company and user IDs, including for listings that already had an owner, and insecure direct object references across multiple front-end and API actions. CVE-2026-75955 (CVSS 5.1) is a reflected XSS and XML injection via an unescaped companyName written into an XML attribute. CVE-2026-75952 (CVSS 4.6) is missing CSRF tokens on many state-changing tasks: contact and quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions. CVE-2026-75953 is an open mail relay, taking the recipient address from the request (contact_id_offer / contact_id_event) rather than the stored offer or event record. Also inside this range is CVE-2020-5182, reverse tabnabbing on the user-supplied business website link, fixed in 5.2.9. Update to 6.2.5 or later rather than stopping at 6.2.3: CMSJunkie shipped two further security releases (6.2.4 on 7 August and 6.2.5 on 14 August 2026), so 6.2.3 and 6.2.4 are still flagged. The JBD Apps add-ons must be updated to their own latest versions as well. Until you can update, treat the site as exposed to unauthenticated remote code execution: restrict front-end access to the directory and review the site for unexpected users, listings and PHP files under the component media and upload folders.
Affected versions: > 4.9.7 and < 6.2.3
Official record: cve.org · NVD
Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.
Affected versions: > 4.9.7 and < 6.2.3
Full advisory: www.cmsjunkie.com
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 25 August 2026.