Reflected XSS Vulnerability in J2Store by j2commerce.com
CVE-2026-78000
5.3MEDIUM
What is CVE-2026-78000?
A reflected cross-site scripting vulnerability in the J2Store extension allows attackers to exploit user input fields, specifically filter_tag, pricefrom, and priceto. This flaw enables a malicious actor to craft a base64-encoded URL that redirects users without proper validation of the destination host. As a result, users may be susceptible to phishing attacks that misuse the shop's trusted domain, causing significant security risks for both the website and its visitors. No authentication is required to exploit this vulnerability, which enhances its severity.
Affected Version(s)
J2Store extension for Joomla 1.0.0-3.3.21
J2Store extension for Joomla 4.0.0-4.0.21
J2Store extension for Joomla 4.1.0-4.1.6
