CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-75952

unknowncovered by 1 sourcefirst seen 2026-08-19
Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive, payment notification send, mobile push). Frontend CSRF needs a registered/listing-owner session; admin CSRF needs a backend admin session.

⚡ Watch CVE-2026-75952

Get an email if CVE-2026-75952 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-75952

CVE.org record

Embed the live status

CVE-2026-75952 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-75952 status](https://www.csirts.com/badge/CVE-2026-75952)](https://www.csirts.com/cve/CVE-2026-75952)