CVE-2020-13996: j2store

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.

Affected products

  • j2store j2store: before 3.3.13 (fixed in 3.3.13)

Published 2020-06-09. Last modified 2026-06-17.