Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-82191MediumCVSS 5.3CVE published 15 September 2026Added to mySites.guru 15 September 2026

J2Store / J2Commerce (com_j2store) 3.3.22 (Joomla 3 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)

J2Store 3.3.22 on the Joomla 3 branch is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 3.3.23 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 3.3.23 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating. The Joomla 3 branch reaches end of life on 19 October 2026, so treat 3.3.23 as time to plan a migration rather than a destination.

Is my site affected?

CVE-2026-82191 is checked by 3 rules. Find the extension and release line your site runs:

ExtensionAffected versionsFixed inWhat to do
J2Store / J2Commercefrom 3.3.22 up to but not including 3.3.233.3.23Update J2Store / J2Commerce to 3.3.23 or later.
J2Store / J2Commercefrom 4.0.22 up to but not including 4.0.234.0.23Update J2Store / J2Commerce to 4.0.23 or later.
J2Store / J2Commercefrom 4.1.7 up to but not including 4.1.84.1.8Update J2Store / J2Commerce to 4.1.8 or later.

How CVE-2026-82191 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

5.3 Medium

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:P User interaction
Passive. Someone has to visit a page

What it does to the site

VC:N Confidentiality
None. Nothing can be read
VI:L Integrity
Low. Some data can be altered
VA:N Availability
None. The site stays up

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

The rule below is rated High for the set of 6 CVEs it covers together, not for this record on its own.

Timeline

  1. 15 September 2026CVE-2026-82191 record published by its CNA
  2. 15 September 2026mySites.guru check added for J2Store / J2Commerce (from 3.3.22 up to but not including 3.3.23)
  3. 15 September 2026mySites.guru check added for J2Store / J2Commerce (from 4.0.22 up to but not including 4.0.23)
  4. 15 September 2026mySites.guru check added for J2Store / J2Commerce (from 4.1.7 up to but not including 4.1.8)
  5. 15 September 2026We published: Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8

Rule details

J2Store / J2Commerce - J2Store / J2Commerce (com_j2store) 4.0.22 (Joomla 4 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)

J2Store 4.0.22 on the Joomla 4 branch is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 4.0.23 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 4.0.23 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating.

Affected versions: ≥ 4.0.22 and < 4.0.23

Full advisory: our disclosure post · www.j2commerce.com

J2Store / J2Commerce - J2Store / J2Commerce (com_j2store) 4.1.7 (Joomla 5 / 6 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)

J2Store 4.1.7, the branch for Joomla 5 and Joomla 6, is affected by six vulnerabilities found and reported to J2Commerce by Phil Taylor of mySites.guru, and fixed in 4.1.8 on 15 September 2026. The most serious needs no login at all: an unauthenticated blind SQL injection in the storefront product and product-tags listing filters (CVE-2026-81567, CVSS 4.0 8.7 High), where the product_types array filter is concatenated into the SQL with no escaping, letting an anonymous visitor read arbitrary database content by boolean or time-based inference. Alongside it: a path-traversal arbitrary file read in the customer download handler that can return files outside the attachment folder including configuration.php (CVE-2026-81568, 8.7 High); a PayPal callback logic flaw letting an unauthenticated request mark ANY order as FAILED regardless of its real payment status (CVE-2026-82189, 8.7 High); incomplete CSRF protection across the checkout and my-profile controllers and admin product-file management, which can silently overwrite a shopper's billing or shipping address before order confirmation (CVE-2026-78081, 7.1 High); an order access token derived from the site secret and a guessable order id rather than generated randomly, and never rotated, so it is forgeable for every order once that secret leaks (CVE-2026-82190, 6.3 Medium); and unescaped request data reflected into the PayPal notify redirect, allowing query-parameter injection (CVE-2026-82191, 5.3 Medium). J2Commerce reports no evidence of exploitation on a live store. Update to J2Store 4.1.8 via Joomla's Components > Update screen or from your J2Commerce.com account. Note that custom template overrides and third-party checkout add-ons (notably Easy Checkout) that ship their own cart, checkout or myprofile templates need the same anti-CSRF token added to their forms, or those actions will return an Invalid Token error after updating.

Affected versions: ≥ 4.1.7 and < 4.1.8

Full advisory: our disclosure post · www.j2commerce.com

Our disclosure post

Other vulnerabilities in J2Store / J2Commerce

Updating for CVE-2026-82191 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

J2Store / J2Commerce

Latest safe version: 4.1.8

All 18 CVEs in J2Store / J2Commerce

References

CVE-2026-82191 questions

Which versions are affected by CVE-2026-82191?
CVE-2026-82191 is covered by 3 rules: J2Store / J2Commerce from 3.3.22 up to but not including 3.3.23; J2Store / J2Commerce from 4.0.22 up to but not including 4.0.23; J2Store / J2Commerce from 4.1.7 up to but not including 4.1.8.
How do I fix CVE-2026-82191?
It depends on the extension and release line your site runs. For J2Store / J2Commerce from 3.3.22 up to but not including 3.3.23: update J2Store / J2Commerce to 3.3.23 or later. For J2Store / J2Commerce from 4.0.22 up to but not including 4.0.23: update J2Store / J2Commerce to 4.0.23 or later. For J2Store / J2Commerce from 4.1.7 up to but not including 4.1.8: update J2Store / J2Commerce to 4.1.8 or later.
How severe is CVE-2026-82191?
Joomla CNA scores it 5.3 (Medium) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and someone has to visit a page.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 6 October 2026.