CVE-2026-90900
— UNSCOREDPublished 2026-09-23 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addReview) accepted submissions without verifying an anti-CSRF token (the check had been commented out in code). An attacker could trick a logged-in user into posting unauthorized reviews or submitting review spam via cross-site requests. Resolved by enforcing Session::checkToken('request') / Session::checkToken('post') in ProductController, injecting HTMLHelper::_('form.token') into the review form template, and appending the session token to the submission payload in review-form.js.
Weaknesses
CWE-352
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2025-15399
- MEDIUMCVE-2026-100524PoC
- MEDIUMCVE-2026-100712PoC
- UNSCOREDCVE-2026-100747
- UNSCOREDCVE-2026-100748
- UNSCOREDCVE-2026-100749
- MEDIUMCVE-2026-100873PoC
- MEDIUMCVE-2026-101093PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.