Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-90902HighPublished 23 September 2026

EasyStore (com_easystore) below 3.0.1 - Unauthenticated Customer Address Disclosure, Authenticated SQL Injection, CSRF and ACL Bypass

EasyStore, the JoomShaper ecommerce component for Joomla, is affected by seven flaws fixed in version 3.0.1, found and reported by mySites.guru. (1) Unauthenticated customer data disclosure: the guest checkout lookup returned a guest customer's saved shipping address (name, street address, city, postcode, country and phone number) to any anonymous visitor who supplied that customer's email address, with no login, session or ownership check. (2) Cross-site request forgery on storefront product reviews: the token check was commented out, so a page a logged-in customer visited could submit reviews in their name. Five further flaws need an administrator session and matter when an admin account is phished or shared, or when an admin is lured to a malicious page: SQL injection in media image deletion and in coupon bulk updates (ids concatenated into an IN() clause), no CSRF token check on the administrator AJAX API, an allowEdit() that always returned true and so bypassed Joomla asset permissions on record edits, and a configuration update that rewrote the site sender name and email in configuration.php with no CSRF token or access check. The flaws were reported against 3.0.0 and are present in the 2.x code as well, so every version below 3.0.1 is treated as affected. Update to EasyStore 3.0.1 or later, released 23 September 2026. The customer address disclosure is a silent read that leaves no file changes, so a clean file scan does not show a site was unaffected. CVE-2026-90899, CVE-2026-90900, CVE-2026-90901, CVE-2026-90902, CVE-2026-90903, CVE-2026-90904 and CVE-2026-90905 are reserved by the Joomla CNA and not yet published.

Affected versions: < 3.0.1

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 23 September 2026.