SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75949

CRITICAL · CVSS 10 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The J-BusinessDirectory extension for Joomla versions prior to 6.2.3 is vulnerable to arbitrary file upload and deletion due to inadequate path containment and weak extension validation, allowing attackers to manipulate file paths. This critical vulnerability, compounded by the absence of a CSRF token, could lead to unauthorized access and potential compromise of the web server. Organizations using this extension should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-75949
Severity
CRITICAL
CVSS
10
EPSS
0.31%

Original NVD Description

Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.