CVE-2026-67359: Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
Published Aug 21, 2026
·Updated
Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any orderid as a query parameter to render the full checkout confirmation page for that order, including line items, prices, and totals.
Affected Software
1 affected component
j2commerce.com J2Store>1.0.0<=3.3.20, >4.0.0<=4.0.20, >4.1.0<=4.1.5
Event History
Aug 21, 2026
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated visitor can exploit it. The issue does not require an account or checkout access.
2
What information could be exposed?
The checkout confirmation page for an order may be rendered, exposing its line items, prices, and totals.
3
What does an attacker need to do?
An attacker needs to supply an order_id value as a query parameter. They can use this to request the confirmation page for an order associated with that identifier.
4
Which J2Store releases are affected?
Affected releases are 1.0.0 through 3.3.20, 4.0.0 through 4.0.20, and 4.1.0 through 4.1.5.