SQL Injection Vulnerability in J-BusinessDirectory by cmsjunkie.com
CVE-2026-75954

9.3CRITICAL

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-75954?

The J-BusinessDirectory extension for Joomla prior to version 6.2.3 is susceptible to an SQL injection vulnerability. This issue arises from an inadequate handling of user input, specifically where search keywords and the ORDER BY clause are concatenated directly into SQL queries, allowing an attacker to manipulate the database queries. Version 6.2.3 addresses this by properly quoting keywords and implementing allow-listing for the sort clause, significantly reducing the risk of exploitation.

Affected Version(s)

J-BusinessDirectory extension for Joomla 1.0.0-6.2.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.