Unauthenticated File Upload Vulnerability in J2Store by Joomla Extension
CVE-2026-67361
What is CVE-2026-67361?
A critical vulnerability has been discovered in the J2Store extension for Joomla, which allows unauthenticated attackers to upload files without any authentication or CSRF token. This security flaw occurs because the file upload endpoint accepts POST requests from unauthenticated users. Furthermore, the installation process fails to adequately secure the uploaded files, as essential directories are left exposed without proper .htaccess or web.config protections. As a result, uploaded files become directly accessible via the web, significantly increasing the risk of exploitation.
Affected Version(s)
J2Store extension for Joomla 1.0.0-3.3.20
J2Store extension for Joomla 4.0.0-4.0.20
J2Store extension for Joomla 4.1.0-4.1.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
