SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81567

HIGH · CVSS 8.7 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The J2Store extension for Joomla is vulnerable to unauthenticated blind SQL injection, allowing attackers to extract sensitive database content, including customer records and stored credentials, through public storefronts that utilize standard product listings or product-tags filters. This high-severity vulnerability poses a significant risk to any organization using affected versions of J2Store, particularly those handling sensitive customer information. Organizations should prioritize patching or mitigating this vulnerability to protect their data integrity and customer privacy.

CVE
CVE-2026-81567
Severity
HIGH
CVSS
8.7
EPSS
0.23%

Original NVD Description

Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer records, order data, stored credentials/tokens) via boolean- or time-based inference, reachable on any public storefront that exposes the standard product listing or product-tags filter.