Reflected XSS and XML Injection in J-BusinessDirectory by Cmsjunkie
CVE-2026-75955

5.1MEDIUM

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-75955?

A security vulnerability has been identified in the J-BusinessDirectory extension for Joomla, where unsanitized data can be reflected in an XML attribute. Specifically, the 'companyName' parameter from user requests is not properly escaped, leading to potential reflected cross-site scripting (XSS) attacks and XML injection. Attackers could exploit this flaw to manipulate the behavior of web applications or execute arbitrary scripts in the context of the user's session, thereby compromising sensitive information and system integrity.

Affected Version(s)

J-BusinessDirectory extension for Joomla 1.0.0-6.2.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.