CVE-2026-67358

Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a valid order token could increment the download limit counter on a download record belonging to a different order. The endpoint also lacked a CSRF token.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 20:16

Updated : 2026-08-26 16:35


NVD link : CVE-2026-67358

Mitre link : CVE-2026-67358

CVE.ORG link : CVE-2026-67358


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-639

Authorization Bypass Through User-Controlled Key