VYPR

J2Store

by Joomla

CVEs (8)

  • CVE-2019-9184CriFeb 26, 2019
    risk 0.67cvss 9.8epss 0.09

    SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

  • CVE-2026-67359HigAug 21, 2026
    risk 0.57cvss epss 0.00

    Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any order_id as a query parameter to render the full checkout confirmation page for that order, including line items, prices,…

  • CVE-2020-13996HigJun 9, 2020
    risk 0.57cvss 8.8epss 0.01

    The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.

  • CVE-2026-74252HigAug 21, 2026
    risk 0.56cvss epss 0.00

    Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a…

  • CVE-2026-67361MedAug 21, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the…

  • CVE-2026-67360MedAug 21, 2026
    risk 0.41cvss epss 0.00

    Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was…

  • CVE-2026-67358MedAug 21, 2026
    risk 0.34cvss epss 0.00

    Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the download limit counter on a download record belonging to a different order. The endpoint also…

  • CVE-2026-67362MedAug 21, 2026
    risk 0.33cvss epss 0.00

    Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the…