Where
-Infinity
0

Vendor Risk Score

See how j2store compares to other vendors in security performance

View Risk Score →
Severity
9.8
SQL Injection
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the productoption[] parameter.

First published (updated )
Severity
8.8
SQL Injection
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.

First published (updated )
Severity
7.5
SQL Injection
AV:N/AC:L/Au:N/C:P/I:P/A:P

Multiple SQL injection vulnerabilities in the J2Store (comj2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) manufacturerids[] parameter to index.php.

First published (updated )
CSRF

Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF save task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - fof.xml grants the carts view's tasks a wildcard true ACL, and FOF only enforces CSRF tokens on back-end HTML requests, not on front-end format=raw requests. J2StoreControllerCarts already scoped remove() to the caller's own session, but never overrode the generic FOF save task, so it remained reachable to insert new cart rows with an attacker-chosen userid/sessionid, or overwrite an existing row by id.

First published (updated )
XSS

Joomla Extension - j2commerce.com - Reflected XSS via filtertag, pricefrom and priceto in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the shop's trusted domain. No authentication required.

First published (updated )

Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - editAddress() redirected non-owners away only when the loaded address row had a non-empty userid belonging to someone else. Guest-checkout address rows have an empty userid, so that check never triggered for them — any logged-in account guessing a small, sequential addressid got a guest customer's full name, street address, and phone number rendered prefilled into the edit form.

First published (updated )

Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - J2StoreControllerApps's appTask delegation path instantiates app-plugin controllers with no ACL check anywhere in the code. It currently returns 403 only as a side effect of fof.xml's wildcard-deny resolving under the singularised ACL key app, which has no explicit allow rule — not because of any deliberate check. Behind that path, applocalizationdata::getInstallerTool() used a caller-influenced table name with no allow-list, both to select a #j2store table for truncation and to build a path to SQL files it then executes — a path-traversal-capable file read/execute.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203