OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-90901

HIGH · CVSS 8.6 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Easy Store extension for Joomla versions 1.0.0 to 3.0.0 is vulnerable to an authenticated SQL injection that allows attackers to access sensitive guest customer information, including full names, addresses, and contact details, by simply providing an email address. This flaw poses a significant risk of PII exposure, making it critical for organizations using this extension to prioritize immediate remediation. Users of the affected Joomla extension should urgently update to the patched version to mitigate potential data breaches.

CVE
CVE-2026-90901
Severity
HIGH
CVSS
8.6
EPSS
0.28%

Original NVD Description

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) parsed the ids parameter as a comma-separated string and imploded it directly into raw SQL IN (...) clauses in Media.php and MediaModel.php without integer casting or parameterization. An authenticated administrator or attacker with access to an admin session could inject arbitrary SQL statements.