Vendor
J2commerce.com vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in J2commerce.com: 0 in the last 7 days and 14 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82191, was published on 15 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 14
- Critical, all time
- 0
- Exploited in the wild
- 0
J2commerce.com technologies
Latest J2commerce.com vulnerabilities
- CVE-2026-82191: J2Store PayPal parameter injection in redirectinfoCVSS 2.7EPSS 0.4%
- CVE-2026-82189: J2Store order status manipulation via unauthenticated requestinfoCVSS 7.5EPSS 0.4%
- CVE-2026-81567: J2Store SQL injection in storefront product listinfoCVSS 7.5EPSS 0.4%
- CVE-2026-78081: J2Commerce J2Store missing CSRF protection in checkout controllersinfoEPSS 0.2%
- CVE-2026-78069: J2Store missing authorization in Apps controllerinfoEPSS 0.4%
- CVE-2026-78065: J2Store guest checkout address disclosure via IDORinfoCVSS 4.3EPSS 0.4%
- CVE-2026-78064: J2Store anonymous cart tampering via FOF save taskinfoCVSS 7.5EPSS 0.4%
- CVE-2026-78000: J2Store reflected XSS via filter_tag, pricefrom, priceto parametersinfoEPSS 0.5%
- CVE-2026-77999: J2Store PayPal IPN signature bypass and order confirmation fraudinfoCVSS 9.1EPSS 0.4%
- CVE-2026-74252: J2Commerce stored XSS in guest checkout billing fieldsinfoCVSS 7.1EPSS 0.5%
- CVE-2026-67362: J2Store open redirect in cart controllerinfoEPSS 0.5%
- CVE-2026-67360: J2Store cross-customer order replication in cart checkoutinfoCVSS 5.7EPSS 0.4%
- CVE-2026-67359: J2Store order information disclosureinfoEPSS 0.4%
- CVE-2026-67358: J2Store download quota manipulation and CSRF bypassinfoCVSS 0EPSS 0.2%
Most severe J2commerce.com vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-77999: J2Store PayPal IPN signature bypass and order confirmation fraudinfoCVSS 9.1EPSS 0.4%
- CVE-2026-82189: J2Store order status manipulation via unauthenticated requestinfoCVSS 7.5EPSS 0.4%
- CVE-2026-78064: J2Store anonymous cart tampering via FOF save taskinfoCVSS 7.5EPSS 0.4%
- CVE-2026-81567: J2Store SQL injection in storefront product listinfoCVSS 7.5EPSS 0.4%
- CVE-2026-74252: J2Commerce stored XSS in guest checkout billing fieldsinfoCVSS 7.1EPSS 0.5%
- CVE-2026-67360: J2Store cross-customer order replication in cart checkoutinfoCVSS 5.7EPSS 0.4%
- CVE-2026-78065: J2Store guest checkout address disclosure via IDORinfoCVSS 4.3EPSS 0.4%
- CVE-2026-82191: J2Store PayPal parameter injection in redirectinfoCVSS 2.7EPSS 0.4%
- CVE-2026-67358: J2Store download quota manipulation and CSRF bypassinfoCVSS 0EPSS 0.2%
- CVE-2026-78000: J2Store reflected XSS via filter_tag, pricefrom, priceto parametersinfoEPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 5 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 5 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 4 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/j2commerce-com.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "J2commerce.com vulnerabilities", https://junglewise.ai/threats/vendors/j2commerce-com, 26 September 2026.