CVE-2026-82189
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-472, CWE-602
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- j2commerce.com J2Store extension for Joomla
- j2commerce.com J2Store extension for Joomla
- j2commerce.com J2Store extension for Joomla
Weakness type
Related vulnerabilities
- CVE-2024-25153 — Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
- CVE-2025-35939 — Craft CMS stores user-provided content in session files
- CVE-2026-14387 — Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sand
- CVE-2026-13796 — Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the
- CVE-2026-11088 — Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rend
- CVE-2021-1293 — Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
- CVE-2021-1295 — Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities
- CVE-2021-1294 — Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers Remote Code Execution Vulnerabilities