CVE-2026-81567
Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer records, order data, stored credentials/tokens) via boolean- or time-based inference, reachable on any public storefront that exposes the standard product listing or product-tags filter.
| CWE | CWE-89 |
| Vendor | j2commerce.com |
| Product | j2store extension for joomla |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for j2commerce.com j2store extension for joomla
Be the first to know when new unknown vulnerabilities affecting j2commerce.com j2store extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
j2commerce.com / J2Store extension for Joomla
1.0.0-3.3.22 4.0.0-4.0.22 4.1.0-4.1.7
Credits
Phil Taylor, mysites.guru