Reflected XSS Vulnerability in J2Store by j2commerce.com
CVE-2026-78000

5.3MEDIUM

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-78000?

A reflected cross-site scripting vulnerability in the J2Store extension allows attackers to exploit user input fields, specifically filter_tag, pricefrom, and priceto. This flaw enables a malicious actor to craft a base64-encoded URL that redirects users without proper validation of the destination host. As a result, users may be susceptible to phishing attacks that misuse the shop's trusted domain, causing significant security risks for both the website and its visitors. No authentication is required to exploit this vulnerability, which enhances its severity.

Affected Version(s)

J2Store extension for Joomla 1.0.0-3.3.21

J2Store extension for Joomla 4.0.0-4.0.21

J2Store extension for Joomla 4.1.0-4.1.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.