
J2Commerce J2Store — coordinated disclosure now public. • CVE-2026-67359 — unauth order disclosure (CVSS 8.7) • CVE-2026-67360 — cross-customer reorder IDOR (8.7) • CVE-2026-67358 — download quota manipulation • CVE-2026-67362 — open redirect Fixed: 3.3.21 / 4.0.21 / 4.1.6 https://t.co/kK7qo7uEu5
Post summary
The tweet announces a coordinated disclosure of several CVEs affecting J2Commerce J2Store, detailing vulnerability types and CVSS scores, and provides fixed version information and a link for remediation.

