Arbitrary File Upload and Deletion Vulnerability in J-BusinessDirectory by cmsjunkie
CVE-2026-75949

10CRITICAL

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-75949?

The J-BusinessDirectory plugin for Joomla is susceptible to security flaws enabling arbitrary file upload and deletion. Specifically, the plugin's upload and remove functionalities do not sufficiently verify the file paths provided by users, potentially allowing attackers to manipulate the paths to point to sensitive directories. Additionally, the lack of a valid CSRF token during file operations raises concerns about cross-site request forgery, further compromising the application's integrity. It's essential for users to update to the latest version to mitigate these vulnerabilities.

Affected Version(s)

J-BusinessDirectory extension for Joomla 1.0.0-6.2.2

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.