SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65759

HIGH · CVSS 8.7 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Easy Store extension for Joomla versions 1.0.0 to 2.0.1 is vulnerable to unauthenticated payment and order forgery due to improper handling of client-side input. This flaw allows attackers to manipulate critical order and payment information, potentially leading to unauthorized transactions. Joomla site administrators using this extension should prioritize immediate remediation to protect against potential exploitation.

CVE
CVE-2026-65759
Severity
HIGH
CVSS
8.7
EPSS
0.26%

Original NVD Description

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders.