CVE-2026-67361

Summary

Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.

Affected Software

VendorProductVersion RangeStatus
j2commerce.comJ2Store extension for Joomla1.0.0-3.3.20affected
j2commerce.comJ2Store extension for Joomla4.0.0-4.0.20affected
j2commerce.comJ2Store extension for Joomla4.1.0-4.1.5affected

Weaknesses

  • CWE-352: CWE-352 Cross-Site Request Forgery (CSRF)
  • CWE-538: CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References