joomshaper.com vulnerabilities
11 CVEs tracked
In recent reporting, JoomShaper vendor is at the center of critical vulnerabilities across two major Joomla extensions: Easy Store (1.0.0-2.0.1) and SP Page Builder (< 6.7.1). For Easy Store, unauthenticated SQL injection (CVE-2026-65761), payment/order forgery (CVE-2026-65759), and authenticated data disclosure (CVE-2026-65760) are reported. SP Page Builder presents a chainable attack surface with unauthenticated SQL injection (CVE-2026-65876) and stored XSS (CVE-2026-66494), alongside authenticated file deletion (CVE-2026-65878) and mail relay via hardcoded secret (CVE-2026-65879). Defenders must immediately upgrade these extensions to the latest versions, prioritizing patches for unauthenticated SQL injection vectors targeting database and session data on public-facing pages.
Azərbaycanca: Son hesabatlarda JoomShaper vendorunun iki əsas Joomla genişləndirilməsi - Easy Store (1.0.0-2.0.1) və SP Page Builder (< 6.7.1) - kritik zəifliklər mərkəzindədir. Easy Store üçün autentifikasiyasız SQL injection (CVE-2026-65761), ödəniş/order forgery (CVE-2026-65759) və autentifikasiyalı məlumat sızması (CVE-2026-65760) bildirilir. SP Page Builder-də isə zəncirvari istismara imkan verən autentifikasiyasız SQL injection (CVE-2026-65876) və stored XSS (CVE-2026-66494), həmçinin autentifikasiyalı fayl silmə (CVE-2026-65878) və mail relay (CVE-2026-65879) mövcuddur. Müdafiəçilər bu genişləndirmələri dərhal ən son versiyalara yeniləməli, xüsusilə ictimaiyyətə açıq səhifələrdə database və sessiya məlumatlarını hədəf alan autentifikasiyasız SQL injection vektorlarına qarşı təcili tədbir görməlidir.
This vendor's CVEs11
This hub is built from skopnix's own reporting on joomshaper.com: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.