CVE-2026-67361

Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - The file upload endpoint accepted POST requests from unauthenticated visitors with no CSRF token. Compounding this, the installer manifest omitted the upload and invoices directories, causing fresh installs to deploy those directories without .htaccess/web.config protection, making uploaded files directly web-accessible.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 20:16

Updated : 2026-08-26 16:35


NVD link : CVE-2026-67361

Mitre link : CVE-2026-67361

CVE.ORG link : CVE-2026-67361


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory