CVE-2026-90905 | JoomShaper Easy Store Extension 1.0.0-3.0.0 Site Configuration Update configuration.php Session::checkToken fromname/mailfrom cross-site request forgery

SecurityVulns

A vulnerability classified as problematic was found in JoomShaper Easy Store Extension 1.0.0-3.0.0. This affects the function Session::checkToken of the file configuration.php of the component Site Configuration Update. Such manipulation of the argument fromname/mailfrom leads to cross-site request forgery.

This vulnerability is documented as CVE-2026-90905. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More