Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-81568HighPublished 15 September 2026

J2Store / J2Commerce (com_j2store) 3.3.22 (Joomla 3 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)

J2Store 3.3.22 on the Joomla 3 branch is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 3.3.23 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 3.3.23 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating. The Joomla 3 branch reaches end of life on 19 October 2026, so treat 3.3.23 as time to plan a migration rather than a destination.

Affected versions: ≥ 3.3.22 and < 3.3.23

Official record: cve.org · NVD

Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.

Affected extensions and versions

J2Store / J2Commerce - J2Store / J2Commerce (com_j2store) 4.0.22 (Joomla 4 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)

J2Store 4.0.22 on the Joomla 4 branch is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 4.0.23 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 4.0.23 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating.

Affected versions: ≥ 4.0.22 and < 4.0.23

Full advisory: our disclosure post · www.j2commerce.com

J2Store / J2Commerce - J2Store / J2Commerce (com_j2store) 4.1.7 (Joomla 5 / 6 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)

J2Store 4.1.7, the branch for Joomla 5 and Joomla 6, is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 4.1.8 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 4.1.8 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating.

Affected versions: ≥ 4.1.7 and < 4.1.8

Full advisory: our disclosure post · www.j2commerce.com

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 15 September 2026.