Vulnerabilities & PatchesEmerging1 src
CVE-2026-78064 - Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
CVE ID : CVE-2026-78064
Published : Sept. 3, 2026, 11:54 a. m.
• 28 minutes ago
Description : Joomla Extension - j2commerce. com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1. 0. 0-3. 3. 21, 4. 0. 0-4. 0. 21, 4. 1. 0-4. 1. 6 - `fof. xml` grants the `carts` view's tasks a wildcard `true` ACL, and FOF only enforces CSRF tokens on back-end HTML requests, not on front-end `format=raw` requests.
`J2StoreControllerCarts` already scoped `remove()` to the caller's own session, but never overrode the generic FOF `save` task, so it remained reachable to insert new cart rows with an attacker-chosen `user_id`/`session_id`, or overwrite an existing row by id.
Severity: 8.8
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...