J2Commerce and Joomla 3
Set 19 October 2026 as the end of life for J2Store 3, with no further releases of any kind after it. Until then the Joomla 3 line has received every security fix the same day as J2Store 4.
Joomla extensions covered: J2Store, J2Commerce. J2Commerce website
What they said
“October 19, 2026 J2Store 3 end of life. No further releases of any kind.”
Said 3 Sep 2026Read it on their siteChecked 2 Oct 2026
Known Joomla 3 vulnerabilities
- High
J2Store / J2Commerce (com_j2store) 3.3.22 (Joomla 3 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)
Affected: ≥ 3.3.22 and < 3.3.23
CVE-2026-78081, CVE-2026-81567, CVE-2026-81568, CVE-2026-82189, CVE-2026-82190, CVE-2026-82191
- Critical
J2Store / J2Commerce (com_j2store) 3.3.21 (Joomla 3 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)
Affected: ≥ 3.3.21 and < 3.3.22
CVE-2026-77999, CVE-2026-78000, CVE-2026-78064, CVE-2026-78065, CVE-2026-78069
- Critical
J2Store / J2Commerce (com_j2store) 4.0.21 (Joomla 4.0 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)
Affected: ≥ 4.0.21 and < 4.0.22
CVE-2026-77999, CVE-2026-78000, CVE-2026-78064, CVE-2026-78065, CVE-2026-78069
- Critical
J2Store / J2Commerce (com_j2store) 4.1.6 (Joomla 4.1 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)
Affected: ≥ 4.1.6 and < 4.1.7
CVE-2026-77999, CVE-2026-78000, CVE-2026-78064, CVE-2026-78065, CVE-2026-78069
- High
J2Store / J2Commerce (com_j2store) below 3.3.21 (Joomla 3 branch) - Unauthenticated File Upload (exploited in the wild), Order Data Disclosure, Stored XSS and IDOR (6 CVEs)
Affected: < 3.3.21
CVE-2026-67358, CVE-2026-67359, CVE-2026-67360, CVE-2026-67361, CVE-2026-67362, CVE-2026-74252, CVE-2020-13996
- High
J2Store / J2Commerce (com_j2store) 4.0.0 to 4.0.20 - Unauthenticated File Upload (exploited in the wild), Order Data Disclosure, Stored XSS and IDOR (6 CVEs)
Affected: ≥ 4.0.0 and < 4.0.21
CVE-2026-67358, CVE-2026-67359, CVE-2026-67360, CVE-2026-67361, CVE-2026-67362, CVE-2026-74252
- High
J2Store / J2Commerce (com_j2store) 4.1.0 to 4.1.5 - Unauthenticated File Upload (exploited in the wild), Order Data Disclosure, Stored XSS and IDOR (6 CVEs)
Affected: ≥ 4.1.0 and < 4.1.6
CVE-2026-67358, CVE-2026-67359, CVE-2026-67360, CVE-2026-67361, CVE-2026-67362, CVE-2026-74252
Our coverage
- Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8
J2Store 3.3.23, 4.0.23 and 4.1.8 fix six flaws mySites.guru reported, including an anonymous blind SQL injection that reads a Joomla shop's whole database.
- J2Store 3 Stops Getting Security Fixes on 19 October 2026
J2Commerce ends J2Store 3 support on 19 October 2026. Six in ten of the J2Store installs we monitor are on that line, and most are three releases behind.
- J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported
J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.
See which of your sites run J2Store
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Is a Joomla 3 site hacked right now?
We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.