CVE-2026-78000
NONE—CVSS v3
—CVSS v2
0.31%
EPSS (exploit probability)
CWE-79CWE
Description
Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL from user input and redirected to it without validating the destination host, enabling phishing using the shop's trusted domain. No authentication required.
Affected routers (0)
No routers currently mapped to this CVE in our database.