VYPR
Medium severityNVD Advisory· Published Aug 21, 2026· Updated Aug 21, 2026

CVE-2026-67361

CVE-2026-67361

Description

Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • Joomla/J2Storellm-fuzzy
    Range: 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.