Open Mail Relay Vulnerability in J-BusinessDirectory by cmsjunkie.com
CVE-2026-75953

Currently unrated

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-75953?

The J-BusinessDirectory extension from cmsjunkie.com is vulnerable to an open mail relay issue, where the recipient address is erroneously derived from user input (contact_id_offer/contact_id_event) rather than being securely sourced from the server-side records. This flaw allows attackers to exploit the mailing functionality to send emails to arbitrary addresses, potentially facilitating email spoofing and privacy violations. Users of J-BusinessDirectory versions prior to 6.2.3 should take immediate steps to upgrade and secure their systems.

Affected Version(s)

J-BusinessDirectory extension for Joomla 1.0.0-6.2.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.