Vulnerabilities > J2Store

DATE CVE VULNERABILITY TITLE RISK
2020-06-09 CVE-2020-13996 SQL Injection vulnerability in J2Store
The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.
network
low complexity
j2store CWE-89
6.5
2019-02-26 CVE-2019-9184 SQL Injection vulnerability in J2Store
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.
network
low complexity
j2store CWE-89
7.5
2015-08-18 CVE-2015-6513 SQL Injection vulnerability in J2Store
Multiple SQL injection vulnerabilities in the J2Store (com_j2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) manufacturer_ids[] parameter to index.php.
network
low complexity
j2store CWE-89
7.5