CVE-2026-82191
Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes the resulting redirect to `com_j2store`'s checkout controller to carry attacker-chosen query parameters instead of only the intended `view=checkout&task=confirmPayment&orderpayment_type=...&paction=process` set — parameter injection/smuggling into that follow-up request. This requires a victim to load the crafted link (`UI:R`/`UI:P`); it does not by itself grant an unauthenticated attacker anything they could not already obtain by requesting the target `com_j2store` URL directly with their own parameters.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-1241
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- j2commerce.com J2Store extension for Joomla
- j2commerce.com J2Store extension for Joomla
- j2commerce.com J2Store extension for Joomla
Weakness type
Related vulnerabilities
- CVE-2023-4695 — Use of Predictable Algorithm in Random Number Generator in pkp/pkp-lib
- CVE-2021-3689 — Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
- CVE-2021-3692 — Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
- CVE-2026-57869 — Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat
- CVE-2025-13079 — Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens
- CVE-2026-6420 — Keylime: keylime: security bypass due to hardcoded tpm quote nonce
- CVE-2026-82190 — Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
- CVE-2026-73576 — In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice i