CVE-2026-67359
HighPublished
Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
- Published
- Aug 21, 2026
- Updated
- Aug 21, 2026
- Assigning CNA
- Joomla
- Evidence observed
- Aug 24, 2026
Primary CVSS
8.7/ 10High
cvelist · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NSummary
Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could supply any order_id as a query parameter to render the full checkout confirmation page for that order, including line items, prices, and totals.
Sources
PoC for J2Store CVE-2026-67358–67362 (J2Commerce security advisory Aug 2026)
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.