Description
Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer records, order data, stored credentials/tokens) via boolean- or time-based inference, reachable on any public storefront that exposes the standard product listing or product-tags filter.
Published: 2026-09-15
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized extraction of sensitive database data
Action: Immediate Patch
AI Analysis

Impact

The J2Store extension for Joomla contains a blind SQL injection vulnerability that is exploitable without authentication. An attacker can use boolean or time based inference to extract arbitrary content from the database, including customer records, order details, and stored credentials or tokens. This weakness is classified as CWE‑89 and directly compromises the confidentiality of all data accessible through the storefront product list or product‑tags filter.

Affected Systems

Affected products are the J2Store extension from j2commerce.com, bundled with Joomla. Vulnerable releases are 1.0.0 through 3.3.2, 4.0.0 through 4.0.22, and 4.1.0 through 4.1.7. The flaw is reachable through any public storefront that exposes the standard product listing or tags filter.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not yet listed in CISA KEV. The likely attack vector is via the public web interface; unauthenticated access to the product list or tags filter allows an attacker to perform blind inference and exfiltrate data remotely.

Generated by OpenCVE AI on September 15, 2026 at 23:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest patched version of J2Store that removes the injection flaw.
  • Restrict public access to the storefront product list or product‑tags filter endpoints using firewall rules or a web application firewall, or disable the features until a patch is applied.
  • Implement parameterized queries or input validation for all database interactions to mitigate future injection weaknesses.

Generated by OpenCVE AI on September 15, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer records, order data, stored credentials/tokens) via boolean- or time-based inference, reachable on any public storefront that exposes the standard product listing or product-tags filter.
Title Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T19:28:53.770Z

Reserved: 2026-08-27T06:42:00.961Z

Link: CVE-2026-81567

cve-icon Vulnrichment

Updated: 2026-09-15T19:28:50.398Z

cve-icon NVD

Status : Received

Published: 2026-09-15T19:17:40.947

Modified: 2026-09-15T20:17:59.603

Link: CVE-2026-81567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:45:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')