SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65761

CRITICAL · CVSS 9.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Easy Store extension for Joomla versions 1.0.0 to 2.0.1 is vulnerable to an unauthenticated SQL injection due to improper validation of order parameters. This flaw allows attackers to execute arbitrary SQL queries, potentially granting them full access to the database, including sensitive information such as credentials and session data. Joomla site administrators using this extension should prioritize remediation to prevent unauthorized data access.

CVE
CVE-2026-65761
Severity
CRITICAL
CVSS
9.3
EPSS
0.24%

Original NVD Description

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.