CVE-2026-82191
CVE-2026-82191 is a medium-severity vulnerability with a CVSS 4.0 base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1241.
Key facts
- Severity: Medium (CVSS 4.0 base score 5.3)
- EPSS exploit prediction: 0% (37th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1241
- Published:
- Last modified:
Description
Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes the resulting redirect to `com_j2store`'s checkout controller to carry attacker-chosen query parameters instead of only the intended `view=checkout&task=confirmPayment&orderpayment_type=...&paction=process` set — parameter injection/smuggling into that follow-up request. This requires a victim to load the crafted link (`UI:R`/`UI:P`); it does not by itself grant an unauthenticated attacker anything they could not already obtain by requesting the target `com_j2store` URL directly with their own parameters.
Frequently asked questions
- What is CVE-2026-82191?
- Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes the resulting redirect to `com_j2store`'s checkout controller to carry attacker-chosen query parameters instead of only the intended `view=checkout&task=confirmPayment&orderpayment_type=...&paction=process` set — parameter injection/smuggling into that follow-up request. This requires a victim to load the crafted link (`UI:R`/`UI:P`); it does not by itself grant an unauthenticated attacker anything they could not already obtain by requesting the target `com_j2store` URL directly with their own parameters.
- How severe is CVE-2026-82191?
- CVE-2026-82191 has a CVSS 4.0 base score of 5.3, rated medium severity.
- Is CVE-2026-82191 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-82191?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-82191 published?
- CVE-2026-82191 was published on 2026-09-15 and last updated on 2026-09-16.
References
Other CWE-1241 vulnerabilities
- CVE-2023-4695 — High (CVSS 8.1): Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- CVE-2026-82190 — Medium (CVSS 6.3): Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22,…
- CVE-2026-73576 — Medium (CVSS 6.3): In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice…
- CVE-2026-6420 — Medium (CVSS 6.3): A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent…
- CVE-2025-13079 — Medium (CVSS 5.3): The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to…
- CVE-2025-32056 — Medium (CVSS 4.0): The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the…