CVE-2026-65759: Joomshaper.com Easy Store Extension For Joomla

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.

Affected products

  • Joomshaper.com Easy Store Extension For Joomla: version 1.0.0-2.0.1 only

Published 2026-07-23. Last modified 2026-07-23.