CVE-2026-67361
Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:A/R:A
- EPSS probability
- 0.17%
- CWE
- CWE-352, CWE-538
- Published
- 2026-08-21
- Last modified
- 2026-08-21
Affected products
- j2commerce.com J2Store extension for Joomla
- j2commerce.com J2Store extension for Joomla
- j2commerce.com J2Store extension for Joomla
Weakness type
Related vulnerabilities
- CVE-2026-87449 — Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36...
- CVE-2026-9215 — A CSRF vulnerability exists in certain NETGEAR XR series devices
- CVE-2026-86724 — AVideo YPTWallet saveBalance.php Cross-Site Request Forgery
- CVE-2026-86719 — WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking
- CVE-2026-86718 — WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php
- CVE-2026-86135 — Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service
- CVE-2026-33920 — Cross-site request forgery in the Guardian/CMC login before 26.3.0
- CVE-2026-76961 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)