CVE-2026-82189
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.
| CWE | CWE-472 CWE-602 |
| Vendor | j2commerce.com |
| Product | j2store extension for joomla |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for j2commerce.com j2store extension for joomla
Be the first to know when new unknown vulnerabilities affecting j2commerce.com j2store extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
j2commerce.com / J2Store extension for Joomla
1.0.0-3.3.22 4.0.0-4.0.22 4.1.0-4.1.7
Credits
Phil Taylor, mysites.guru