PatchSiren

J2Store CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM J2Store CVE published 2026-08-21

CVE-2026-67362

The J2Store extension for Joomla has an open redirect vulnerability in versions 1.0.0-3.3.20, 4.0.0-4.0.20, and 4.1.0-4.1.5. This vulnerability allows attackers to redirect users to malicious sites, potentially leading to phishing attacks, as four task handlers accept a base64-encoded URL from user input and redirect to it without validating the destination host. No authentication is required to exploit t [truncated]