{"id":"CVE-2026-82191","title":"Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an a…","summary":"Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an a…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-1241"],"vendor":"j2commerce.com","product":"J2Store extension for Joomla","affected":["j2store_extension_for_joomla 1.0.0-3.3.22","j2store_extension_for_joomla 4.0.0-4.0.22","j2store_extension_for_joomla 4.1.0-4.1.7"],"published":"2026-09-15","updated":"2026-09-16","sourceUpdated":"2026-09-16T19:28:06.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82191","references":[{"url":"https://www.j2commerce.com/","label":"security@joomla.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T19:29:07.410580Z"},"cvssSource":"cna","ingestedAt":"2026-09-15T19:42:58.811Z","epss":0.00264,"epssPercentile":0.18598,"slug":"CVE-2026-82191","body":"## Overview\n\nJoomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes the resulting redirect to `com_j2store`'s checkout controller to carry attacker-chosen query parameters instead of only the intended `view=checkout&task=confirmPayment&orderpayment_type=...&paction=process` set — parameter injection/smuggling into that follow-up request. This requires a victim to load the crafted link (`UI:R`/`UI:P`); it does not by itself grant an unauthenticated attacker anything they could not already obtain by requesting the target `com_j2store` URL directly with their own parameters.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}