Description
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
Published: 2026-07-23
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated SQL injection in the Easy Store extension for Joomla caused by improper validation of order parameters. Attackers can inject arbitrary SQL that allows reading the entire database, including user credentials and session data, which directly compromises confidentiality and may enable account takeover. This impact is based on the description’s explicit mention of full DB read access.

Affected Systems

The affected component is the Easy Store extension for Joomla provided by joomshaper.com. Versions 1.0.0 through 2.0.1 are vulnerable.

Risk and Exploitability

With a CVSS score of 9.3, the flaw is considered critical. The EPSS score of less than 1% indicates a low probability of broad exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability is unauthenticated and relies on standard web requests targeting order parameters; therefore the likely attack vector is network‑based and application‑level, meaning any remote user who can reach the Joomla site can potentially exploit it by sending crafted requests to the vulnerable endpoint. The impact is full database read access, which can lead to significant data exposure and potentially account compromise, although the latter is inferred from the database breach potential and not explicitly stated in the description.

Generated by OpenCVE AI on August 3, 2026 at 21:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Easy Store extension to the latest patched version that resolves the SQL injection.
  • If an upgrade cannot be performed immediately, disable or uninstall the Easy Store extension so the vulnerable entry point is removed.
  • Configure a web application firewall to block SQL injection patterns targeting the order parameters used by the extension.

Generated by OpenCVE AI on August 3, 2026 at 21:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper.com
Joomshaper.com easy Store Extension For Joomla
Vendors & Products Joomshaper.com
Joomshaper.com easy Store Extension For Joomla

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
Title Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Joomshaper.com Easy Store Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:53:01.925Z

Reserved: 2026-07-22T20:46:13.953Z

Link: CVE-2026-65761

cve-icon Vulnrichment

Updated: 2026-07-23T19:06:25.464Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T17:16:30.433

Modified: 2026-07-23T20:17:22.897

Link: CVE-2026-65761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:30:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')