Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Easy Store extension for Joomla — Vulnerabilities & Security Advisories 10

All 10 CVE vulnerabilities found in Easy Store extension for Joomla, with AI-generated Chinese analysis, references, and POCs.

Vendor: joomshaper.com

CVE ID Title CVSS Severity Published
CVE-2026-90903 Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 CWE-352 7.2 High 2026-09-23
CVE-2026-90901 Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 CWE-74 8.6 High 2026-09-23
CVE-2026-90905 Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 CWE-352 7.2 High 2026-09-23
CVE-2026-90902 Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 CWE-74 8.2 High 2026-09-23
CVE-2026-90904 Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 CWE-284 8.6 High 2026-09-23
CVE-2026-90899 Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 CWE-200 8.2 High 2026-09-23
CVE-2026-90900 Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 CWE-352 5.3 Medium 2026-09-23
CVE-2026-65759 Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 CWE-284 8.7 High 2026-07-23
CVE-2026-65761 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 CWE-89 9.3 Critical 2026-07-23
CVE-2026-65760 Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 CWE-284 9.2 Critical 2026-07-23

All 10 known CVE vulnerabilities affecting Easy Store extension for Joomla with full Chinese analysis, references, and POCs where available.