CVE-2026-82191
Received Received - Intake

Reflected Parameter Injection in J2Store Joomla Extension

Vulnerability report for CVE-2026-82191, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Joomla! Project

Description

Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes the resulting redirect to `com_j2store`'s checkout controller to carry attacker-chosen query parameters instead of only the intended `view=checkout&task=confirmPayment&orderpayment_type=...&paction=process` set β€” parameter injection/smuggling into that follow-up request. This requires a victim to load the crafted link (`UI:R`/`UI:P`); it does not by itself grant an unauthenticated attacker anything they could not already obtain by requesting the target `com_j2store` URL directly with their own parameters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
j2commerce j2store From 1.0.0 (inc) to 3.3.2 (inc)
j2commerce j2store From 4.0.0 (inc) to 4.0.22 (inc)
j2commerce j2store From 4.1.0 (inc) to 4.1.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1241 The device uses an algorithm that is predictable and generates a pseudo-random number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a Joomla extension called J2Store. It allows an attacker to craft a malicious link that, when clicked by a victim, injects attacker-controlled parameters into a PayPal payment confirmation request. The issue is due to unescaped request data being reflected into the redirect URL, enabling parameter injection or smuggling into the follow-up request.

Detection Guidance

This vulnerability involves reflected parameter injection in J2Store's PayPal notify endpoint. To detect it, inspect web server access logs for unusual query parameters in requests to com_j2store's checkout controller, particularly those containing unexpected values in the crafted link. Look for patterns like additional parameters beyond the standard view=checkout&task=confirmPayment set.

Impact Analysis

The impact depends on how the injected parameters are processed. While it does not grant unauthenticated attackers additional access, it could allow manipulation of payment flows or redirection to malicious sites. Victims must click a crafted link for exploitation, making it a user interaction-dependent attack.

Compliance Impact

This vulnerability involves reflected parameter injection in a payment processing flow, which could allow attackers to manipulate redirect URLs. While not directly violating GDPR or HIPAA, such flaws may undermine data integrity and confidentiality during payment processing, potentially leading to unauthorized data exposure or transaction manipulation. Compliance impact depends on how the vulnerability is exploited in practice.

Mitigation Strategies

Update J2Store to the latest patched version (1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 or newer) immediately. If updating is not possible, restrict access to the PayPal notify endpoint via web server rules or firewall until a patch is applied. Monitor for suspicious activity targeting this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82191. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart