CVE-2026-67361CWE-352CWE-538csrf

CVE-2026-67361

published August 22, 2026

CVSS
6.9
EPSS
0%
Percentile
6.0
In the wild
Unconfirmed
What it is

Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.

The record
Technical detail
CVSS
6.9 · NONE
CVSS v4.0
6.9 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:A/R:A
EPSS
0.00165 · 6.0th percentile
Weaknesses
CWE-352 · Cross-Site Request Forgery (CSRF); CWE-538 · Insertion of Sensitive Information into Externally-Accessible File or Directory
Published
2026-08-22T00:16Z
References (1)
EPSS history
Timeline
  • 21 AUG 19:23Z
    Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
    cvelistv5