What is CVE-2026-65760?
Improper access checks in Joomla Easy Store extension versions 1.0.0 through 2.0.1 allow authenticated users to retrieve order and customer information of any order, leading to cross-customer data disclosure. Affected systems should be upgraded to the latest version immediately.
Azərbaycanca: Joomla-nın Easy Store əlavəsinin 1.0.0-dan 2.0.1-ə qədər versiyalarında zəif giriş yoxlamaları aşkarlanıb ki, bu da sistemdəki qualifed istifadəçilərə istənilən sifarişin və müştəri məlumatının əldə edilməsinə imkan verir. Bu boşluq kross-müştəri məlumat sızmasına səbəb olur. Təsirə məruz qalan sistemlərin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Joomla Easy Store extension are affected by CVE-2026-65760?
This vulnerability affects Easy Store extension versions 1.0.0 through 2.0.1.
What security issue does CVE-2026-65760 cause?
This vulnerability allows authenticated users to retrieve order and customer information of any order, leading to cross-customer data disclosure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.