CVE-2026-90903
Last modified
CVE-2026-90903 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. All other administrative AJAX endpoints (orders, coupons, media, customers, settings, tags, categories, reviews, and collections) accepted state-changing requests without checking anti-CSRF tokens.
Description
Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. All other administrative AJAX endpoints (orders, coupons, media, customers, settings, tags, categories, reviews, and collections) accepted state-changing requests without checking anti-CSRF tokens. An attacker could trick a logged-in administrator into triggering unauthorized state modifications across the store backend. Resolved by implementing global CSRF verification in ApiController::execute() for all state-changing HTTP methods (POST, PUT, PATCH, DELETE) via Session::checkToken().
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| joomshaper.com | Easy Store extension for Joomla | 1.0.0-3.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-90903?
How severe is CVE-2026-90903?
How do I fix CVE-2026-90903?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90898Bifrost registers MCP clients through its management API. A …9.8
- CVE-2026-90899Joomla Extension - joomshaper.com - Unauthenticated PII Expo…8.2
- CVE-2026-9090Casdoor versions 2.362.0 and earlier contain a vulnerability…9.1
- CVE-2026-90900Joomla Extension - joomshaper.com - Missing CSRF Token Verif…5.3
- CVE-2026-90901Joomla Extension - joomshaper.com - Authenticated, Privilege…8.6
- CVE-2026-90902Joomla Extension - joomshaper.com - Authenticated, Privilege…8.6
- CVE-2026-90904Joomla Extension - joomshaper.com - Broken Access Control (A…8.6
- CVE-2026-90905Joomla Extension - joomshaper.com - Missing CSRF and Access …7.2
- CVE-2026-9091Casdoor versions 2.362.0 and earlier contain a logic flaw in…5.3
- CVE-2026-90919LightLLM through 1.2.0 contains a remote code execution vuln…9.8
- CVE-2026-9092Casdoor versions 2.362.0 and earlier contain a vulnerability…9.1
- CVE-2026-90922The Paid Membership Subscriptions WordPress plugin before 3…5.3
Are you affected by CVE-2026-90903?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
