Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-65761CriticalCVSS 9.3CVE published 23 July 2026

EasyStore (com_easystore) below 2.0.2 - Unauthenticated SQL Injection, Unauthenticated Order Forgery and Cross-Customer Invoice Disclosure

EasyStore, the JoomShaper ecommerce component for Joomla, is affected by three flaws in version 2.0.1 and every earlier release, found and reported by mySites.guru. (1) Unauthenticated order forgery: the checkout repayment task built the order from client-supplied JSON including the payment status and wrote it to the database with no login, no CSRF token, no ownership check and no contact with any payment gateway, so an anonymous request could mark any order paid (goods released without payment) and rewrite arbitrary fields on any order id. CWE-862 and CWE-639, CVSS 4.0 8.7 High. (2) Unauthenticated SQL injection: the product list sort parameter passed its direction into the query ORDER BY clause without an allow-list, giving an anonymous visitor a read of any table in the database including Joomla user accounts, password hashes and the site secret. CWE-89, CVSS 4.0 8.7 High. (3) Cross-customer order and invoice disclosure: the order detail page and printable invoice checked only that a user was logged in, never that the order belonged to them, and order ids are sequential, so any registered customer could read every other customer name, email address, billing and shipping address, phone number and purchase history. CWE-639, CVSS 4.0 7.1 High. Update to EasyStore 2.0.2 or later, released 23 July 2026. JoomShaper shipped 2.0.2 with no security advisory and described the three fixes as routine changelog lines. A web application firewall filtering SQL may block the injection but does nothing about the order forgery or the invoice exposure, so it is mitigation rather than a fix. Both the invoice exposure and the SQL injection are silent reads that leave no file changes, so a clean file scan does not indicate a site was unaffected. A CVE has been applied for through the Joomla CNA and is not yet assigned. Assigned CVE-2026-65759, CVE-2026-65760, CVE-2026-65761 (all affect <= 2.0.1, fixed 2.0.2).

Is my site affected?

Affected
EasyStore before 2.0.2
Fixed in
2.0.2
What to do
Update EasyStore to 2.0.2 for this flaw, or to 3.0.1 or later, which no rule we check matches.

How CVE-2026-65761 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

9.3 Critical

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:H Confidentiality
High. Everything the site holds can be read
VI:H Integrity
High. Data and files can be altered at will
VA:H Availability
High. The site can be taken down

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

The rule below is rated High for the set of 3 CVEs it covers together, not for this record on its own.

Timeline

  1. 23 July 2026CVE-2026-65761 record published by its CNA
  2. 23 July 2026We published: Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru

Rule details

Our disclosure post

Other vulnerabilities in EasyStore

Updating for CVE-2026-65761 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

EasyStore

Latest safe version: 3.0.1

All 10 CVEs in EasyStore

References

CVE-2026-65761 questions

Which versions are affected by CVE-2026-65761?
CVE-2026-65761 affects EasyStore before 2.0.2. The fix is in 2.0.2.
How do I fix CVE-2026-65761?
Update EasyStore to 2.0.2 for this flaw, or to 3.0.1 or later, which no rule we check matches. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2026-65761?
Joomla CNA scores it 9.3 (Critical) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.