{"schema_version":1,"title":"JoomShaper Easy Store vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in JoomShaper Easy Store: 6 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-90905, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/easy-store","json_url":"https://junglewise.ai/threats/technologies/easy-store.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/easy-store","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":9,"critical":0,"exploited":0,"last_7_days":6,"last_30_days":6,"last_90_days":9,"last_365_days":9},"latest":[{"cve":"CVE-2026-90905","epss":0.0026,"slug":"cve-2026-90905-joomla-extension-joomshaper-com-missing-csrf-and-access-control","title":"Joomla Easy Store extension missing CSRF and access control","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.673+00:00","url":"https://junglewise.ai/threats/cve-2026-90905-joomla-extension-joomshaper-com-missing-csrf-and-access-control"},{"cve":"CVE-2026-90904","epss":0.0031,"slug":"cve-2026-90904-joomla-extension-joomshaper-com-broken-access-control-acl-bypass","title":"Joomla Easy Store extension access control bypass in ApiController","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.543+00:00","url":"https://junglewise.ai/threats/cve-2026-90904-joomla-extension-joomshaper-com-broken-access-control-acl-bypass"},{"cve":"CVE-2026-90903","epss":0.0017,"slug":"cve-2026-90903-joomla-extension-joomshaper-com-missing-csrf-token-verification","title":"Joomla Easy Store extension missing CSRF token verification in AJAX endpoints","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.417+00:00","url":"https://junglewise.ai/threats/cve-2026-90903-joomla-extension-joomshaper-com-missing-csrf-token-verification"},{"cve":"CVE-2026-90902","epss":0.0025,"slug":"cve-2026-90902-joomla-extension-joomshaper-com-authenticated-privileged-sql","title":"Joomla Easy Store SQL injection in coupon bulk update","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.283+00:00","url":"https://junglewise.ai/threats/cve-2026-90902-joomla-extension-joomshaper-com-authenticated-privileged-sql"},{"cve":"CVE-2026-90901","epss":0.004,"slug":"cve-2026-90901-joomla-extension-joomshaper-com-authenticated-privileged-sql","title":"Joomla Easy Store SQL injection in media deletion","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.15+00:00","url":"https://junglewise.ai/threats/cve-2026-90901-joomla-extension-joomshaper-com-authenticated-privileged-sql"},{"cve":"CVE-2026-90900","epss":0.0017,"slug":"cve-2026-90900-joomla-extension-joomshaper-com-missing-csrf-token-verification","title":"Joomla Easy Store CSRF vulnerability in product review submission","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.02+00:00","url":"https://junglewise.ai/threats/cve-2026-90900-joomla-extension-joomshaper-com-missing-csrf-token-verification"},{"cve":"CVE-2026-65761","cvss":9.3,"slug":"cve-2026-65761-joomshaper-easystore-sql-injection-in-product-list-sorting","title":"JoomShaper EasyStore SQL injection in product list sorting","severity":"info","exploited":false,"published_at":"2026-07-23T17:16:30.433+00:00","url":"https://junglewise.ai/threats/cve-2026-65761-joomshaper-easystore-sql-injection-in-product-list-sorting"},{"cve":"CVE-2026-65760","cvss":9.2,"slug":"cve-2026-65760-joomshaper-easy-store-improper-access-control-in-order-views","title":"JoomShaper Easy Store improper access control in order views","severity":"info","exploited":false,"published_at":"2026-07-23T17:16:30.31+00:00","url":"https://junglewise.ai/threats/cve-2026-65760-joomshaper-easy-store-improper-access-control-in-order-views"},{"cve":"CVE-2026-65759","cvss":8.7,"slug":"cve-2026-65759-joomshaper-easy-store-unauthenticated-order-forgery-in-checkout","title":"JoomShaper Easy Store unauthenticated order forgery in checkout repay task","severity":"info","exploited":false,"published_at":"2026-07-23T17:16:30.19+00:00","url":"https://junglewise.ai/threats/cve-2026-65759-joomshaper-easy-store-unauthenticated-order-forgery-in-checkout"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":6}],"related":[{"name":"JoomShaper SP Page Builder","slug":"sp-page-builder","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/sp-page-builder"},{"name":"JoomShaper Helix-Ultimate","slug":"helix-ultimate","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/helix-ultimate"},{"name":"JoomShaper SP Property","slug":"sp-property","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/sp-property"},{"name":"JoomShaper SP Page Builder Pro","slug":"sp-page-builder-pro","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/sp-page-builder-pro"}],"technology":{"hub":true,"name":"JoomShaper Easy Store","slug":"easy-store","vendor":{"name":"JoomShaper","slug":"joomshaper","url":"https://junglewise.ai/threats/vendors/joomshaper"},"aliases":[],"category":"extension","homepage":"https://www.joomshaper.com/easystore","description":"An e-commerce extension for the Joomla content management system.","url":"https://junglewise.ai/threats/technologies/easy-store"},"most_severe":[{"cve":"CVE-2026-65761","cvss":9.3,"slug":"cve-2026-65761-joomshaper-easystore-sql-injection-in-product-list-sorting","title":"JoomShaper EasyStore SQL injection in product list sorting","severity":"info","exploited":false,"published_at":"2026-07-23T17:16:30.433+00:00","url":"https://junglewise.ai/threats/cve-2026-65761-joomshaper-easystore-sql-injection-in-product-list-sorting"},{"cve":"CVE-2026-65760","cvss":9.2,"slug":"cve-2026-65760-joomshaper-easy-store-improper-access-control-in-order-views","title":"JoomShaper Easy Store improper access control in order views","severity":"info","exploited":false,"published_at":"2026-07-23T17:16:30.31+00:00","url":"https://junglewise.ai/threats/cve-2026-65760-joomshaper-easy-store-improper-access-control-in-order-views"},{"cve":"CVE-2026-65759","cvss":8.7,"slug":"cve-2026-65759-joomshaper-easy-store-unauthenticated-order-forgery-in-checkout","title":"JoomShaper Easy Store unauthenticated order forgery in checkout repay task","severity":"info","exploited":false,"published_at":"2026-07-23T17:16:30.19+00:00","url":"https://junglewise.ai/threats/cve-2026-65759-joomshaper-easy-store-unauthenticated-order-forgery-in-checkout"},{"cve":"CVE-2026-90901","epss":0.004,"slug":"cve-2026-90901-joomla-extension-joomshaper-com-authenticated-privileged-sql","title":"Joomla Easy Store SQL injection in media deletion","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.15+00:00","url":"https://junglewise.ai/threats/cve-2026-90901-joomla-extension-joomshaper-com-authenticated-privileged-sql"},{"cve":"CVE-2026-90904","epss":0.0031,"slug":"cve-2026-90904-joomla-extension-joomshaper-com-broken-access-control-acl-bypass","title":"Joomla Easy Store extension access control bypass in ApiController","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.543+00:00","url":"https://junglewise.ai/threats/cve-2026-90904-joomla-extension-joomshaper-com-broken-access-control-acl-bypass"},{"cve":"CVE-2026-90905","epss":0.0026,"slug":"cve-2026-90905-joomla-extension-joomshaper-com-missing-csrf-and-access-control","title":"Joomla Easy Store extension missing CSRF and access control","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.673+00:00","url":"https://junglewise.ai/threats/cve-2026-90905-joomla-extension-joomshaper-com-missing-csrf-and-access-control"},{"cve":"CVE-2026-90902","epss":0.0025,"slug":"cve-2026-90902-joomla-extension-joomshaper-com-authenticated-privileged-sql","title":"Joomla Easy Store SQL injection in coupon bulk update","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.283+00:00","url":"https://junglewise.ai/threats/cve-2026-90902-joomla-extension-joomshaper-com-authenticated-privileged-sql"},{"cve":"CVE-2026-90903","epss":0.0017,"slug":"cve-2026-90903-joomla-extension-joomshaper-com-missing-csrf-token-verification","title":"Joomla Easy Store extension missing CSRF token verification in AJAX endpoints","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.417+00:00","url":"https://junglewise.ai/threats/cve-2026-90903-joomla-extension-joomshaper-com-missing-csrf-token-verification"},{"cve":"CVE-2026-90900","epss":0.0017,"slug":"cve-2026-90900-joomla-extension-joomshaper-com-missing-csrf-token-verification","title":"Joomla Easy Store CSRF vulnerability in product review submission","severity":"info","exploited":false,"published_at":"2026-09-23T19:19:43.02+00:00","url":"https://junglewise.ai/threats/cve-2026-90900-joomla-extension-joomshaper-com-missing-csrf-token-verification"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}