Unauthenticated File Upload Vulnerability in J2Store by Joomla Extension
CVE-2026-67361

6.9MEDIUM

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-67361?

A critical vulnerability has been discovered in the J2Store extension for Joomla, which allows unauthenticated attackers to upload files without any authentication or CSRF token. This security flaw occurs because the file upload endpoint accepts POST requests from unauthenticated users. Furthermore, the installation process fails to adequately secure the uploaded files, as essential directories are left exposed without proper .htaccess or web.config protections. As a result, uploaded files become directly accessible via the web, significantly increasing the risk of exploitation.

Affected Version(s)

J2Store extension for Joomla 1.0.0-3.3.20

J2Store extension for Joomla 4.0.0-4.0.20

J2Store extension for Joomla 4.1.0-4.1.5

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Terry Harker, Co-Founder of byteKultur GmbH, Zurich
.