CVE-2026-81567
Received Received - Intake

Unauthenticated Blind SQL Injection in J2Store Extension

Vulnerability report for CVE-2026-81567, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Joomla! Project

Description

Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer records, order data, stored credentials/tokens) via boolean- or time-based inference, reachable on any public storefront that exposes the standard product listing or product-tags filter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
j2commerce j2store to 3.3.2 (inc)
j2commerce j2store to 4.0.22 (inc)
j2commerce j2store to 4.1.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated blind SQL injection vulnerability in the J2Store Joomla extension affecting versions 1.0.0-3.3.2, 4.0.0-4.0.22, and 4.1.0-4.1.7. It allows attackers to extract arbitrary database content like customer records, order data, or credentials via boolean or time-based inference methods. The flaw is reachable on any public storefront page showing product listings or product-tag filters.

Detection Guidance

To detect this vulnerability, inspect Joomla sites running J2Store versions 1.0.0-3.3.2, 4.0.0-4.0.22, or 4.1.0-4.1.7 for unusual database queries or slow responses on product listing pages. Check server logs for repeated time-based delays or boolean-based SQL errors in requests to /index.php?option=com_j2store&view=products or similar endpoints.

Impact Analysis

An attacker could exploit this to steal sensitive data such as customer information, payment details, or admin credentials. They might also manipulate orders, delete records, or gain full control of the database. Since no authentication is required, any public-facing store using vulnerable versions is at risk.

Compliance Impact

This vulnerability could lead to unauthorized access and exposure of personal data, violating GDPR's data protection requirements and potentially HIPAA if health-related data is involved. Organizations may face fines, legal penalties, and reputational damage due to non-compliance with data security standards.

Mitigation Strategies

Immediately update J2Store to the latest patched version to address the unauthenticated blind SQL injection vulnerability in the product list and product-tags filter. If updating is not possible, consider disabling the vulnerable extension or restricting access to the storefront until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81567. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart