SQL Injection Vulnerability in J-BusinessDirectory by cmsjunkie.com
CVE-2026-75954
9.3CRITICAL
What is CVE-2026-75954?
The J-BusinessDirectory extension for Joomla prior to version 6.2.3 is susceptible to an SQL injection vulnerability. This issue arises from an inadequate handling of user input, specifically where search keywords and the ORDER BY clause are concatenated directly into SQL queries, allowing an attacker to manipulate the database queries. Version 6.2.3 addresses this by properly quoting keywords and implementing allow-listing for the sort clause, significantly reducing the risk of exploitation.
Affected Version(s)
J-BusinessDirectory extension for Joomla 1.0.0-6.2.2
