OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-90903

HIGH · CVSS 7.2 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Easy Store extension for Joomla is vulnerable due to inadequate CSRF token verification across multiple administrative AJAX API endpoints, allowing attackers to exploit this weakness and perform unauthorized state changes in the store backend. This high-severity vulnerability poses a significant risk to any Joomla site using the affected extension, particularly those with administrative access. Joomla administrators and security teams should prioritize applying the patch to mitigate potential exploitation.

CVE
CVE-2026-90903
Severity
HIGH
CVSS
7.2
EPSS
0.17%

Original NVD Description

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. All other administrative AJAX endpoints (orders, coupons, media, customers, settings, tags, categories, reviews, and collections) accepted state-changing requests without checking anti-CSRF tokens. An attacker could trick a logged-in administrator into triggering unauthorized state modifications across the store backend. Resolved by implementing global CSRF verification in ApiController::execute() for all state-changing HTTP methods (POST, PUT, PATCH, DELETE) via Session::checkToken().