CVE-2026-67360

Summary

Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked.

Affected Software

VendorProductVersion RangeStatus
j2commerce.comJ2Store extension for Joomla1.0.0-3.3.20affected
j2commerce.comJ2Store extension for Joomla4.0.0-4.0.20affected
j2commerce.comJ2Store extension for Joomla4.1.0-4.1.5affected

Weaknesses

  • CWE-639: CWE-639 (Authorization Bypass Through User-Controlled Key)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References