CVE Feed

    Dashboard / CVE / CVE-2026-75950

    CVE-2026-75950

    Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings.

    Published:Aug 19, 2026
    Last Modified:Aug 21, 2026
    EPS:Aug 19, 2026
    EPSS Score:0.00295
    CVSS Score:6.9

    Affected Products

    Vendor
    Cmsjunkie.com
    Product
    J-businessdirectory Extension For Joomla

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High