Vulnerabilities > J2Store > J2Store > 3.1.5

DATE CVE VULNERABILITY TITLE RISK
2020-06-09 CVE-2020-13996 SQL Injection vulnerability in J2Store
The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.
network
low complexity
j2store CWE-89
6.5
2015-08-18 CVE-2015-6513 SQL Injection vulnerability in J2Store
Multiple SQL injection vulnerabilities in the J2Store (com_j2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) manufacturer_ids[] parameter to index.php.
network
low complexity
j2store CWE-89
7.5