PT-2026-79438 · J2Store · J2Store

·

CVE-2026-74252

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions J2Store versions 1.0.0 through 3.3.20 J2Store versions 4.0.0 through 4.0.20 J2Store versions 4.1.0 through 4.1.5
Description Stored Cross-Site Scripting (XSS) exists in the guest checkout billing address fields. An unauthenticated attacker can store unsanitized HTML in fields such as billing first name by exploiting a filter bypass in the Input::getArray() function combined with the PHP variables order=EGPCS configuration, where cookies override POST data in the $ REQUEST superglobal.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74252

Affected Products

J2Store