CVE-2026-78064: j2commerce.com j2store Extension For Joomla

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml` grants the `carts` view's tasks a wildcard `true` ACL, and FOF only enforces CSRF tokens on back-end HTML requests, not on front-end `format=raw` requests. `J2StoreControllerCarts` already scoped `remove()` to the caller's own session, but never overrode the generic FOF `save` task, so it remained reachable to insert new cart rows with an attacker-chosen `user_id`/`session_id`, or overwrite an existing row by id.

Affected products

  • j2commerce.com j2store Extension For Joomla: version 1.0.0-3.3.21 only; version 4.0.0-4.0.21 only; version 4.1.0-4.1.6 only

Published 2026-09-03. Last modified 2026-09-03.