Junglewise Threat Intelligence

CVE-2026-81567: J2Store SQL injection in storefront product list

CVE-2026-81567 · Severity: info · CVSS 7.5 · Published 2026-09-15

Executive brief

J2Store is a popular Joomla e-commerce extension that manages online stores and customer data. An unauthenticated SQL injection vulnerability in the product listing and filtering features allows attackers to extract sensitive database contents—including customer records, order information, and stored credentials—without any authentication or user interaction required. This vulnerability affects any J2Store installation with a public storefront.

Technical details

This is a blind SQL injection vulnerability in the storefront product list and product-tags filter parameters of J2Store. The vulnerability is unauthenticated, meaning no login is required to exploit it. Attackers can leverage boolean-based or time-based inference techniques to extract arbitrary database content, including customer records, order data, and credentials. The attack is reachable directly on any publicly exposed product listing page. The affected versions are 1.0.0–3.3.2, 4.0.0–4.0.22, and 4.1.0–4.1.7; patch availability from the vendor has not been confirmed in the advisory text.

Affected products

  • j2commerce.com J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7

Timeline

  • 2026-09-15: disclosed

References

Related threats