VYPR

J2commerce

by WordPress

CVEs (1)

  • CVE-2026-78069CriSep 3, 2026
    risk 0.62cvss epss

    Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s `appTask` delegation path instantiates app-plugin controllers with no ACL check anywhere in the code. It…