VYPR

Easy Store

by Joomshaper.com

CVEs (2)

  • CVE-2026-65759Jul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order…

  • CVE-2026-65761Jul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.