CyberRota Analysis
AI-GeneratedThe J-BusinessDirectory extension for Joomla versions prior to 6.2.3 is vulnerable to reflected XSS and XML injection due to the unescaped output of the companyName parameter in XML attributes. This vulnerability could allow attackers to inject malicious scripts or manipulate XML data, potentially compromising user data or application integrity. Joomla administrators and developers using this extension should prioritize patching to mitigate the risk.
CVE
CVE-2026-75955
Severity
MEDIUM
CVSS
5.1
EPSS
0.32%
Original NVD Description
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.