
📁 Joomla J-BusinessDirectory < 6.2.3: client-controlled _path_type enables arbitrary file upload/deletion via path traversal. No auth required. CVSS 10. CVE-2026-75949 — upgrade now. #cybersecurity #ciso #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-75949?utm_campaign=x https://t.co/zHjAMM1WcU
Post summary
A Joomla J‑BusinessDirectory vulnerability (CVE‑2026‑75949) allows unauthenticated attackers to upload or delete files via path traversal with a CVSS score of 10, and users are urged to upgrade immediately.

