SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75951

MEDIUM · CVSS 6.9 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The J-BusinessDirectory extension for Joomla versions prior to 6.2.3 is vulnerable to Insecure Direct Object Reference, allowing unauthorized users to access sensitive data through multiple frontend and API actions. This could lead to data exposure or manipulation, impacting the integrity and confidentiality of user information. Joomla administrators and developers utilizing this extension should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-75951
Severity
MEDIUM
CVSS
6.9
EPSS
0.29%

Original NVD Description

Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3