What the vulnerability does
01Description
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
Explanation of Vulnerability in Simple Terms
02Summary
The Easy Store extension for Joomla contains a SQL injection vulnerability in versions 1.0.0 through 2.0.1. An attacker can inject malicious SQL commands through unfiltered input, potentially reading or modifying the site database. No authentication is required to exploit this vulnerability. Sites running affected versions should update immediately.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete data from the site database without authentication.
Potential impact on your site
04Site Impact
Attackers can steal customer data, modify product listings, or take the store offline.
Conditions required to exploit
05Prerequisites
Network access to the site; no login or user interaction required.
Key dates
06Disclosure timeline
July 23, 2026
CVE published
July 24, 2026
Record updated