Vulnerabilities > J2Store > J2Store > 3.3.1

DATE CVE VULNERABILITY TITLE RISK
2020-06-09 CVE-2020-13996 SQL Injection vulnerability in J2Store
The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.
network
low complexity
j2store CWE-89
6.5
2019-02-26 CVE-2019-9184 SQL Injection vulnerability in J2Store
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.
network
low complexity
j2store CWE-89
7.5