Threat intelligence dashboard
CVE-2026-82189high

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or flipping already-fulfilled orders back to `FAILED` to cause operational confusion (unwarranted refunds/cancellations, customer-support load). Unlike the earlier confirmation-fraud issue, this required no correct payment amount or transaction data at all.

Risk score

8.7

CVSS 4.0

Vendor
j2commerce.com
Product
J2Store extension for Joomla
CWE
CWE-472, CWE-602
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

J2Store extension for Joomla

j2commerce.com

Version / rangeStatusType
1.0.0-3.3.22affected
4.0.0-4.0.22affected
4.1.0-4.1.7affected

Technical metrics

8.7

CVSS 4.0

Severity
high
Source
Joomla
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N