Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78064— Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6

Quick assessment

Affected
j2commerce.com J2Store extension for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla 扩展 - j2commerce.com - J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 中通过继承的 FOF 任务实现匿名用户篡改购物车记录 授予 视图任务通配符 的访问控制列表(ACL),而 FOF 仅对后台 HTML 请求强制校验 CSRF 令牌,对前端 请求则不进行校验。 已将 操作限定在调用者自身的会话范围内,但从未重写通用的 FOF 任务,导致攻击者可以通过指定任意的 / 插入新的购物车记录,或者通过 id 覆盖现有的购物车记录。

CVSS 8.8 · High EPSS 0.24% · P15

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 3

VendorProduct Version RangeStatus
j2commerce.com J2Store extension for Joomla 1.0.0-3.3.21 affected
4.0.0-4.0.21 affected
4.1.0-4.1.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78064

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml` grants the `carts` view's tasks a wildcard `true` ACL, and FOF only enforces CSRF tokens on back-end HTML requests, not on front-end `format=raw` requests. `J2StoreControllerCarts` already scoped `remove()` to the caller's own session, but never overrode the generic FOF `save` task, so it remained reachable to insert new cart rows with an attacker-chosen `user_id`/`session_id`, or overwrite an existing row by id.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
j2commerce.com J2Store extension for Joomla 1.0.0-3.3.21 -

II. Public POCs for CVE-2026-78064

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78064

登录查看更多情报信息。

Vendor Pages for CVE-2026-78064 (1)

Same Patch Batch · j2commerce.com · 2026-09-03 · 5 CVEs total

CVE-2026-78069 9.5 CRITICAL Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation ch
CVE-2026-77999 8.7 HIGH Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to ord
CVE-2026-78065 7.1 HIGH Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated
CVE-2026-78000 5.3 MEDIUM Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.

IV. Related Vulnerabilities

V. Comments for CVE-2026-78064

No comments yet


Leave a comment