Unrated severityNVD Advisory· Published Jul 23, 2026· Updated Jul 24, 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
CVE-2026-65761
Description
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
Affected products
2- Range: 1.0.0-2.0.1
- Range: 1.0.0-2.0.1
Patches
Vulnerability mechanics
References
2- mysites.guru/blog/easystore-security-disclosure/mitrethird-party-advisory
- www.joomshaper.com/easystoremitreproduct
News mentions
0No linked articles in our index yet.