CVE-2026-78064 | j2commerce J2Store Extension up to 3.3.21/4.0.21/4.1.6 Cart fof.xml save user_id/session_id cross-site request forgery
A vulnerability has been found in j2commerce J2Store Extension up to 3.3.21/4.0.21/4.1.6 and classified as problematic. This vulnerability affects the function Save of the file fof.xml of the component Cart. This manipulation of the argument user_id/session_id causes cross-site request forgery.
This vulnerability is handled as CVE-2026-78064. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More