CVE-2026-78000

NONE
CVSS v3
CVSS v2
0.31% EPSS (exploit probability)
CWE-79CWE

Description

Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the shop's trusted domain. No authentication required.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references