Technology · J2commerce.com
J2commerce.com J2Store vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 16 vulnerabilities in J2commerce.com J2Store: 0 in the last 7 days and 16 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82191, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 16
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest J2commerce.com J2Store vulnerabilities
- CVE-2026-82191: J2Store PayPal parameter injection in redirectinfoCVSS 2.7EPSS 0.4%
- CVE-2026-82190: J2Store predictable order access tokeninfoCVSS 0EPSS 0.3%
- CVE-2026-82189: J2Store order status manipulation via unauthenticated requestinfoCVSS 7.5EPSS 0.4%
- CVE-2026-81568: J2Store arbitrary file read via path traversal in download handlerinfoCVSS 6.5EPSS 0.5%
- CVE-2026-81567: J2Store SQL injection in storefront product listinfoCVSS 7.5EPSS 0.4%
- CVE-2026-78081: J2Commerce J2Store missing CSRF protection in checkout controllersinfoEPSS 0.2%
- CVE-2026-78069: J2Store missing authorization in Apps controllerinfoEPSS 0.4%
- CVE-2026-78065: J2Store guest checkout address disclosure via IDORinfoCVSS 4.3EPSS 0.4%
- CVE-2026-78064: J2Store anonymous cart tampering via FOF save taskinfoCVSS 7.5EPSS 0.4%
- CVE-2026-78000: J2Store reflected XSS via filter_tag, pricefrom, priceto parametersinfoEPSS 0.5%
- CVE-2026-77999: J2Store PayPal IPN signature bypass and order confirmation fraudinfoCVSS 9.1EPSS 0.4%
- CVE-2026-67362: J2Store open redirect in cart controllerinfoEPSS 0.5%
- CVE-2026-67361: J2Store unauthenticated file upload with missing directory protectioninfoEPSS 0.2%
- CVE-2026-67360: J2Store cross-customer order replication in cart checkoutinfoCVSS 5.7EPSS 0.4%
- CVE-2026-67359: J2Store order information disclosureinfoEPSS 0.4%
- CVE-2026-67358: J2Store download quota manipulation and CSRF bypassinfoCVSS 0EPSS 0.2%
Most severe J2commerce.com J2Store vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-77999: J2Store PayPal IPN signature bypass and order confirmation fraudinfoCVSS 9.1EPSS 0.4%
- CVE-2026-82189: J2Store order status manipulation via unauthenticated requestinfoCVSS 7.5EPSS 0.4%
- CVE-2026-78064: J2Store anonymous cart tampering via FOF save taskinfoCVSS 7.5EPSS 0.4%
- CVE-2026-81567: J2Store SQL injection in storefront product listinfoCVSS 7.5EPSS 0.4%
- CVE-2026-81568: J2Store arbitrary file read via path traversal in download handlerinfoCVSS 6.5EPSS 0.5%
- CVE-2026-67360: J2Store cross-customer order replication in cart checkoutinfoCVSS 5.7EPSS 0.4%
- CVE-2026-78065: J2Store guest checkout address disclosure via IDORinfoCVSS 4.3EPSS 0.4%
- CVE-2026-82191: J2Store PayPal parameter injection in redirectinfoCVSS 2.7EPSS 0.4%
- CVE-2026-82190: J2Store predictable order access tokeninfoCVSS 0EPSS 0.3%
- CVE-2026-67358: J2Store download quota manipulation and CSRF bypassinfoCVSS 0EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 5 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 6 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/j2store.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "J2commerce.com J2Store vulnerabilities", https://junglewise.ai/threats/technologies/j2store, 26 September 2026.