SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75952

MEDIUM · CVSS 4.6 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The J-BusinessDirectory extension for Joomla versions prior to 6.2.3 is vulnerable to cross-site request forgery (CSRF) due to missing tokens on various AJAX and state-changing tasks, including contact forms, cart operations, and administrative actions. This vulnerability could allow an attacker to perform unauthorized actions on behalf of users with valid sessions, potentially compromising sensitive data or altering system configurations. Joomla administrators and users of the J-BusinessDirectory extension should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-75952
Severity
MEDIUM
CVSS
4.6
EPSS
0.16%

Original NVD Description

Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive, payment notification send, mobile push). Frontend CSRF needs a registered/listing-owner session; admin CSRF needs a backend admin session.