SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the productoption[] parameter.
The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.
Multiple SQL injection vulnerabilities in the J2Store (comj2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) manufacturerids[] parameter to index.php.