EasyStore (com_easystore) below 3.0.1 - Unauthenticated Customer Address Disclosure, Authenticated SQL Injection, CSRF and ACL Bypass
EasyStore, the JoomShaper ecommerce component for Joomla, is affected by seven flaws fixed in version 3.0.1, found and reported by mySites.guru. (1) Unauthenticated customer data disclosure: the guest checkout lookup returned a guest customer's saved shipping address (name, street address, city, postcode, country and phone number) to any anonymous visitor who supplied that customer's email address, with no login, session or ownership check. (2) Cross-site request forgery on storefront product reviews: the token check was commented out, so a page a logged-in customer visited could submit reviews in their name. Five further flaws need an administrator session and matter when an admin account is phished or shared, or when an admin is lured to a malicious page: SQL injection in media image deletion and in coupon bulk updates (ids concatenated into an IN() clause), no CSRF token check on the administrator AJAX API, an allowEdit() that always returned true and so bypassed Joomla asset permissions on record edits, and a configuration update that rewrote the site sender name and email in configuration.php with no CSRF token or access check. The flaws were reported against 3.0.0 and are present in the 2.x code as well, so every version below 3.0.1 is treated as affected. Update to EasyStore 3.0.1 or later, released 23 September 2026. The customer address disclosure is a silent read that leaves no file changes, so a clean file scan does not show a site was unaffected. CVE-2026-90899, CVE-2026-90900, CVE-2026-90901, CVE-2026-90902, CVE-2026-90903, CVE-2026-90904 and CVE-2026-90905 were published by the Joomla CNA on 23 September 2026, crediting Phil Taylor of mySites.guru.
Affected versions: < 3.0.1
Full advisory: our disclosure post
EasyStore (com_easystore) below 2.0.2 - Unauthenticated SQL Injection, Unauthenticated Order Forgery and Cross-Customer Invoice Disclosure
EasyStore, the JoomShaper ecommerce component for Joomla, is affected by three flaws in version 2.0.1 and every earlier release, found and reported by mySites.guru. (1) Unauthenticated order forgery: the checkout repayment task built the order from client-supplied JSON including the payment status and wrote it to the database with no login, no CSRF token, no ownership check and no contact with any payment gateway, so an anonymous request could mark any order paid (goods released without payment) and rewrite arbitrary fields on any order id. CWE-862 and CWE-639, CVSS 4.0 8.7 High. (2) Unauthenticated SQL injection: the product list sort parameter passed its direction into the query ORDER BY clause without an allow-list, giving an anonymous visitor a read of any table in the database including Joomla user accounts, password hashes and the site secret. CWE-89, CVSS 4.0 8.7 High. (3) Cross-customer order and invoice disclosure: the order detail page and printable invoice checked only that a user was logged in, never that the order belonged to them, and order ids are sequential, so any registered customer could read every other customer name, email address, billing and shipping address, phone number and purchase history. CWE-639, CVSS 4.0 7.1 High. Update to EasyStore 2.0.2 or later, released 23 July 2026. JoomShaper shipped 2.0.2 with no security advisory and described the three fixes as routine changelog lines. A web application firewall filtering SQL may block the injection but does nothing about the order forgery or the invoice exposure, so it is mitigation rather than a fix. Both the invoice exposure and the SQL injection are silent reads that leave no file changes, so a clean file scan does not indicate a site was unaffected. A CVE has been applied for through the Joomla CNA and is not yet assigned. Assigned CVE-2026-65759, CVE-2026-65760, CVE-2026-65761 (all affect <= 2.0.1, fixed 2.0.2).
Affected versions: < 2.0.2
Full advisory: our disclosure post