Vendor
JoomShaper vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 38 vulnerabilities in JoomShaper: 7 in the last 7 days and 35 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-90905, was published on 23 September 2026. 5 technologies have a page of their own.
- Last 7 days
- 7
- Last 90 days
- 35
- Critical, all time
- 1
- Exploited in the wild
- 1
About JoomShaper
A software developer and provider of templates and extensions for the Joomla content management system.
JoomShaper technologies
Latest JoomShaper vulnerabilities
- CVE-2026-90905: Joomla Easy Store extension missing CSRF and access controlinfoEPSS 0.3%
- CVE-2026-90904: Joomla Easy Store extension access control bypass in ApiControllerinfoEPSS 0.3%
- CVE-2026-90903: Joomla Easy Store extension missing CSRF token verification in AJAX endpointsinfoEPSS 0.2%
- CVE-2026-90902: Joomla Easy Store SQL injection in coupon bulk updateinfoEPSS 0.3%
- CVE-2026-90901: Joomla Easy Store SQL injection in media deletioninfoEPSS 0.4%
- CVE-2026-90900: Joomla Easy Store CSRF vulnerability in product review submissioninfoEPSS 0.2%
- CVE-2026-90899: Joomla Easy Store insecure guest checkout IDORinfoEPSS 0.3%
- CVE-2026-79701: JoomShaper SP Page Builder Pro CAPTCHA bypass in addonsinfoCVSS 7.5EPSS 0.4%
- CVE-2026-81566: JoomShaper SP Page Builder missing access control in menu item creationinfoEPSS 0.4%
- CVE-2026-81565: JoomShaper SP Page Builder arbitrary file upload directory traversalinfoCVSS 7.5EPSS 0.5%
- CVE-2026-81564: JoomShaper SP Page Builder arbitrary file rename via missing directory confinementinfoEPSS 0.5%
- CVE-2026-79700: JoomShaper SP Page Builder Pro CAPTCHA bypass in optin_form addoninfoEPSS 0.4%
- CVE-2026-78375: JoomShaper SP Page Builder SQL injection in Content plugininfoCVSS 6.5EPSS 0.4%
- CVE-2026-78085: JoomShaper SP Property path traversal in gallery image managementinfoCVSS 0EPSS 0.5%
- CVE-2026-78303: JoomShaper SP Property unvalidated email destination in booking formsinfoEPSS 0.4%
- CVE-2026-78302: JoomShaper SP Property stored XSS via unescaped output in viewsinfoCVSS 6.5EPSS 0.4%
- CVE-2026-78084: JoomShaper SP Property authorization bypass in gallery managementinfoEPSS 0.3%
- CVE-2026-78083: JoomShaper SP Property CSRF token bypass in booking and contact formsinfoEPSS 0.2%
- CVE-2026-78082: JoomShaper SP Property unauthenticated SQL injection in search filteringinfoCVSS 7.5EPSS 0.5%
- CVE-2026-78079: JoomShaper Helix Ultimate open redirect via Base64 return parameterinfoEPSS 0.4%
- CVE-2026-78078: JoomShaper Helix Ultimate privileged file upload bypass via content spoofinginfoEPSS 0.4%
- CVE-2026-78077: JoomShaper Helix Ultimate stored XSS in MegaMenu layoutinfoEPSS 0.4%
- CVE-2026-78076: JoomShaper Helix Ultimate broken access control in MegaMenu settingsinfoEPSS 0.4%
- CVE-2026-78075: JoomShaper Helix Ultimate broken object-level authorization in blog image deletioninfoEPSS 0.4%
- CVE-2026-65879: JoomShaper SP Page Builder unauthenticated mail relay via hardcoded secretinfoCVSS 6.9
Most severe JoomShaper vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-48908: JoomShaper SP Page Builder arbitrary file upload in Joomlacriticalexploited in the wildCVSS 10EPSS 0.8%
- CVE-2017-20266: Joomshaper SP Movie Database SQL injection in searchword parameterhighCVSS 8.2
- CVE-2026-48909: JoomShaper SP LMS remote code execution via cookie deserializationinfoCVSS 9.5
- CVE-2026-65761: JoomShaper EasyStore SQL injection in product list sortinginfoCVSS 9.3
- CVE-2026-65876: JoomShaper SP Page Builder SQL injection in loadMoreArticlesinfoCVSS 9.2
- CVE-2026-65766: JoomShaper SP Page Builder SQL injection in Dynamic Content endpointinfoCVSS 9.2
- CVE-2026-65760: JoomShaper Easy Store improper access control in order viewsinfoCVSS 9.2
- CVE-2026-57830: JoomShaper Helix Ultimate unauthenticated arbitrary file deletioninfoCVSS 8.8
- CVE-2026-65759: JoomShaper Easy Store unauthenticated order forgery in checkout repay taskinfoCVSS 8.7
- CVE-2026-57829: JoomShaper Helix Ultimate unauthenticated stored XSSinfoCVSS 8.7
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 2 | 0 | |
| 20 Jul 2026 | 3 | 0 | |
| 27 Jul 2026 | 5 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 5 | 0 | |
| 7 Sep 2026 | 6 | 0 | |
| 14 Sep 2026 | 6 | 0 | |
| 21 Sep 2026 | 7 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/joomshaper.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "JoomShaper vulnerabilities", https://junglewise.ai/threats/vendors/joomshaper, 26 September 2026.