SecAlerts
J

JoomShaper

Security Risk Profile

59
/100
medium

Security Risk Score

Comprehensive risk assessment based on 16 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 19, 2026 to present

16
Total CVEs
13
Critical+High
2
Exploited
13
Unpatched

Threat Assessment

Avg CVSS
8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
13
Critical/High
Risk Level
59/100
medium
⚠️ 2 Active Exploits🆕 7Fresh (<7d)📈 11 in Last 30 Days

Severity Distribution

Critical
3
High
10
Medium
3
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
4
2
CSRF
3
3
Infoleak
1
4
Path Traversal
1
5
XSS
1

Most Affected Products

1. JoomShaper Easy Store7
2. JoomShaper SP Page Builder3
3. JoomShaper Helix Ultimate2
4. JoomShaper SP Page Builder Pro1
5. JoomShaper SP Page Builder (Free and Pro)1

Recent Vulnerabilities

See more →
CVE-2026-90903
CVSS 7.2high

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0

Sep 23, 2026🔧 No Patch
CVE-2026-90901
CVSS 8.6high

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0

Sep 23, 2026🔧 No Patch
CVE-2026-90905
CVSS 7.2high

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0

Sep 23, 2026🔧 No Patch
CVE-2026-90902
CVSS 8.2high

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0

Sep 23, 2026🔧 No Patch
CVE-2026-90904
CVSS 8.6high

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0

Sep 23, 2026🔧 No Patch
CVE-2026-90899
CVSS 8.2high

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0

Sep 23, 2026🔧 No Patch
CVE-2026-90900
CVSS 5.3medium

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0

Sep 23, 2026🔧 No Patch
CVE-2026-79701
CVSS 6.9medium

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0

Sep 14, 2026🔧 No Patch
CVE-2026-81564
CVSS 7.0high

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0

Sep 14, 2026🔧 No Patch
CVE-2026-78082
CVSS 9.3critical

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4

Sep 10, 2026🔧 No Patch

Monitor JoomShaper in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

JoomShaper Security Vulnerabilities & Risk Score | 16 CVEs | SecAlerts - SecAlerts