Joomla 扩展 - j2commerce.com - J2Store 1.0.0-3.3.20、4.0.0-4.0.20、4.1.0-4.1.5 中存在未经身份验证的文件上传漏洞,且目标目录缺少必要的保护机制。该文件上传接口接受来自未认证用户的 POST 请求,且未实施 CSRF(跨站请求伪造)令牌验证。此外,安装清单(installer manifest)未包含对 upload 和 invoices 目录的保护配置,导致全新安装时这些目录部署后缺少 .htaccess 或 web.config 文件保护,从而
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.20 |
affected |
4.0.0-4.0.20 |
affected | ||
4.1.0-4.1.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| j2commerce.com | J2Store extension for Joomla | 1.0.0-3.3.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67359 | 8.7 HIGH | Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4 |
| CVE-2026-74252 | 8.6 HIGH | Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, |
| CVE-2026-67360 | 6.3 MEDIUM | Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3. |
| CVE-2026-67358 | 5.3 MEDIUM | Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4 |
| CVE-2026-67362 | 5.1 MEDIUM | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3. |
No comments yet