What is CVE-2026-65761?
An unauthenticated SQL injection vulnerability has been identified in the Joomshaper Easy Store extension (versions 1.0.0-2.0.1) for Joomla. Improper validation of order parameters allows attackers to gain full database read access, including credentials and sessions. Immediate update to the latest extension version is required.
Azərbaycanca: Joomshaper-in Easy Store genişlənmə modulunda (1.0.0-2.0.1) autentifikasiya olmamış istifadəçilər üçün SQL injection zəifliyi aşkarlanıb. Bu, sifariş parametrlərinin düzgün yoxlanılmaması səbəbindən yaranır və təcavüzkarlara verilənlər bazasına tam giriş, o cümlədən etimadnamələr və sessiyaları oxuma imkanı verir. Genişlənmə modulu dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: joomshaper.com
FAQ2
Which versions of the Joomshaper Easy Store extension are affected by CVE-2026-65761?
This vulnerability affects Joomshaper Easy Store extension versions 1.0.0 through 2.0.1.
Why is this SQL injection vulnerability dangerous?
Due to improper validation of order parameters, unauthenticated attackers can gain full database read access, allowing them to read sensitive data such as credentials and sessions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.