CVE-2026-67358: Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
Published Aug 21, 2026
·Updated
Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the download limit counter on a download record belonging to a different order. The endpoint also lacked a CSRF token.
Affected Software
1 affected component
j2commerce.com J2Store>=1.0.0<=3.3.20, >=4.0.0<=4.0.20, >=4.1.0<=4.1.5
Event History
Aug 21, 2026
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user needs a valid order token. The issue involves manipulating a download record that belongs to a different order.
2
What access or request conditions are required?
Exploitation requires an authenticated session and a valid order token. The affected endpoint also does not require a CSRF token.
3
Which J2Store releases are affected?
Affected versions are 1.0.0 through 3.3.20, 4.0.0 through 4.0.20, and 4.1.0 through 4.1.5.