CVE-2026-65761
Severity CVSS v4.0:
CRITICAL
Type:
CWE-89
SQL Injection
Publication date:
23/07/2026
Last modified:
23/07/2026
Description
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



