CVE-2026-67361
Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.
| CWE | CWE-352 CWE-538 |
| Vendor | j2commerce.com |
| Product | j2store extension for joomla |
| Published | Aug 21, 2026 |
| Last Updated | Aug 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for j2commerce.com j2store extension for joomla
Be the first to know when new unknown vulnerabilities affecting j2commerce.com j2store extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
j2commerce.com / J2Store extension for Joomla
1.0.0-3.3.20 4.0.0-4.0.20 4.1.0-4.1.5
Credits
Terry Harker, Co-Founder of byteKultur GmbH, Zurich