SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65760

CRITICAL · CVSS 9.2 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Easy Store extension for Joomla versions 1.0.0 to 2.0.1 is vulnerable due to improper access controls, enabling authenticated users to access and retrieve order and personal information from other customers. This flaw poses a significant risk of data leakage and privacy violations, making it critical for Joomla site administrators using this extension to prioritize immediate remediation. Organizations handling sensitive customer data should assess their exposure and implement necessary security measures to mitigate this vulnerability.

CVE
CVE-2026-65760
Severity
CRITICAL
CVSS
9.2
EPSS
0.25%

Original NVD Description

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.