CVE-2026-81568 | j2commerce J2Store Extension up to 3.3.2/4.0.22/4.1.7 Download getFilePath task path traversal
A vulnerability described as problematic has been identified in j2commerce J2Store Extension up to 3.3.2/4.0.22/4.1.7. This impacts the function J2StoreModelOrderdownloads::getFilePath of the component Download. The manipulation of the argument task results in path traversal.
This vulnerability is identified as CVE-2026-81568. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More