Affected versions: ≥ 3.3.22 and < 3.3.23
Full advisory: our disclosure post · www.j2commerce.com
J2Store 3.3.22 on the Joomla 3 branch is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 3.3.23 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 3.3.23 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating. The Joomla 3 branch reaches end of life on 19 October 2026, so treat 3.3.23 as time to plan a migration rather than a destination.
CVE-2026-82190 is checked by 3 rules. Find the extension and release line your site runs:
| Extension | Affected versions | Fixed in | What to do |
|---|---|---|---|
| J2Store / J2Commerce | from 3.3.22 up to but not including 3.3.23 | 3.3.23 | Update J2Store / J2Commerce to 3.3.23 or later. |
| J2Store / J2Commerce | from 4.0.22 up to but not including 4.0.23 | 4.0.23 | Update J2Store / J2Commerce to 4.0.23 or later. |
| J2Store / J2Commerce | from 4.1.7 up to but not including 4.1.8 | 4.1.8 | Update J2Store / J2Commerce to 4.1.8 or later. |
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
6.3 Medium
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NThe rule below is rated High for the set of 6 CVEs it covers together, not for this record on its own.
Affected versions: ≥ 3.3.22 and < 3.3.23
Full advisory: our disclosure post · www.j2commerce.com
J2Store / J2Commerce - J2Store / J2Commerce (com_j2store) 4.0.22 (Joomla 4 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)
J2Store 4.0.22 on the Joomla 4 branch is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 4.0.23 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 4.0.23 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating.
Affected versions: ≥ 4.0.22 and < 4.0.23
Full advisory: our disclosure post · www.j2commerce.com
J2Store / J2Commerce - J2Store / J2Commerce (com_j2store) 4.1.7 (Joomla 5 / 6 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)
J2Store 4.1.7, the branch for Joomla 5 and Joomla 6, is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 4.1.8 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 4.1.8 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating.
Affected versions: ≥ 4.1.7 and < 4.1.8
Full advisory: our disclosure post · www.j2commerce.com
Updating for CVE-2026-82190 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
Latest safe version: 4.1.8
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.
Rules current as of 6 October 2026.