SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-75955

MEDIUM · CVSS 5.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The J-BusinessDirectory extension for Joomla versions prior to 6.2.3 is vulnerable to reflected XSS and XML injection due to the unescaped output of the companyName parameter in XML attributes. This vulnerability could allow attackers to inject malicious scripts or manipulate XML data, potentially compromising user data or application integrity. Joomla administrators and developers using this extension should prioritize patching to mitigate the risk.

CVE
CVE-2026-75955
Severity
MEDIUM
CVSS
5.1
EPSS
0.32%

Original NVD Description

Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.