SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75953

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The J-BusinessDirectory extension for Joomla versions prior to 6.2.3 is vulnerable due to an open mail relay that allows attackers to send emails to arbitrary addresses by manipulating request parameters. This flaw can lead to unauthorized email disclosure and potential spam abuse, posing a risk to both users and the integrity of the server. Joomla site administrators using this extension should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-75953
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.