CVE-2026-67360Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could supply another customer's order_id to copy their cart contents and address data into the attacker's session. The CSRF token was validated but ownership was not checked.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-21: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 108-21
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • mürrez@murrezsec
    Disclosure

    J2Commerce J2Store — coordinated disclosure now public. • CVE-2026-67359 — unauth order disclosure (CVSS 8.7) • CVE-2026-67360 — cross-customer reorder IDOR (8.7) • CVE-2026-67358 — download quota manipulation • CVE-2026-67362 — open redirect Fixed: 3.3.21 / 4.0.21 / 4.1.6 https://t.co/kK7qo7uEu5

    Post summary

    J2Commerce J2Store has publicly disclosed four CVEs, detailing each vulnerability's nature and CVSS scores, and has released fixed version information.

    0001062
    601 followersView on X

Explore more