CVE-2026-75953
Received Received - Intake

Open Mail Relay in J-BusinessDirectory Joomla Extension

Vulnerability report for CVE-2026-75953, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Joomla! Project

Description

Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cmsjunkie j-businessdirectory to 6.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an open mail relay issue in the J-BusinessDirectory Joomla extension version before 6.2.3. It allows an attacker to send emails to arbitrary addresses by manipulating recipient details in the request parameters contact_id_offer or contact_id_event, instead of using the legitimate server-side offer or event record.

Impact Analysis

This vulnerability could allow attackers to send phishing emails or spam from your server, potentially damaging your reputation. It may also lead to unauthorized use of your email system for malicious purposes, increasing the risk of blacklisting your domain.

Compliance Impact

This vulnerability allows an attacker to send emails to arbitrary addresses by manipulating recipient details in requests. This could lead to unauthorized data disclosure or phishing attempts, potentially violating GDPR's data protection principles or HIPAA's confidentiality requirements if sensitive information is involved.

Mitigation Strategies

Update J-BusinessDirectory to version 6.2.3 or later to address the open mail relay vulnerability. Review mail server logs for suspicious outbound emails sent via the affected extension.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75953. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart