CSRF Vulnerability in J2Store for Joomla by j2commerce
CVE-2026-78081

7.1HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-78081?

The J2Store extension for Joomla possesses a vulnerability due to missing CSRF protection on critical controllers including cart, checkout, and myprofile. This flaw allows a malicious actor to exploit an active checkout session of a user, leading to unauthorized modifications of billing and shipping addresses. Such attacks can redirect orders to the attacker's control, posing significant security risks. Additionally, this vulnerability enables tampering with saved profile addresses through the saveAddress() method, all while the forged requests are executed with the privileges of the victim's session, preventing cross-account data access.

Affected Version(s)

J2Store extension for Joomla 1.0.0-3.3.22

J2Store extension for Joomla 4.0.0-4.0.22

J2Store extension for Joomla 4.1.0-4.1.7

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.