CVE-2026-65761: Joomshaper.com Easy Store Extension For Joomla

Critical severity, CVSS 9.3. EPSS: 1% chance of exploitation in the next 30 days.

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.

Affected products

  • Joomshaper.com Easy Store Extension For Joomla: version 1.0.0-2.0.1 only

Published 2026-07-23. Last modified 2026-07-23.