CVE-2026-75955: Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3
Published Aug 19, 2026
·Updated
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.
Affected Software
1 affected component
J-BusinessDirectory<6.2.3
Event History
Aug 19, 2026
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
J-BusinessDirectory versions earlier than 6.2.3 are affected. The issue is in handling the companyName value from a request.
2
What does an attacker need to exploit this issue?
An attacker needs to be able to submit a request containing a crafted companyName value. The provided data does not state whether authentication is required or identify the affected endpoint.
3
What is the recommended remediation?
Upgrade J-BusinessDirectory to version 6.2.3 or later. The provided data does not include a workaround for installations that cannot be upgraded immediately.