EasyStore 3.0 SECURITY HOLES - Question | JoomShaper

is live, now with multi-currency selling.

EasyStore 3.0 SECURITY HOLES

SC

Stuart Clark

EasyStore 5 hours ago

I'm not even surprised to find that EasyStore 3.0 continued to have HUGE SECURITY BUGS, even after previous updates to address them!

To this end, EasyStore 3.0.1 has now been released, fixing SEVEN CVE entries!!! - Yes - SEVEN!

Unfortunately, JoomShaper haven't yet fixed ANY of the bugs which make EasyStore 3.0 unusable in a production website!

0
5 Answers
SC
Stuart Clark
Accepted Answer
5 hours ago #234228

From the changelog (so no guarantee it is accurate):

  • Fixed an unauthenticated guest checkout IDOR vulnerability that could expose PII. [CVE-2026-90899]
  • Fixed missing CSRF token verification in storefront product review submissions. [CVE-2026-90900]
  • Fixed an authenticated SQL injection vulnerability in media image deletion. [CVE-2026-90901]
  • Fixed an authenticated SQL injection vulnerability in coupon bulk update operations. [CVE-2026-90902]
  • Fixed missing CSRF token verification across administrator AJAX API endpoints. [CVE-2026-90903]
  • Fixed an ACL bypass vulnerability in administrator API record editing operations. [CVE-2026-90904]
  • Fixed missing CSRF token verification and access control checks in site configuration updates. [CVE-2026-90905]
0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 5 hours ago #234231

Hello Stuart Clark,

From the changelog (so no guarantee it is accurate):

With due respect, your response is disrespectful. We have submitted the CVEs to Joomla! Security Team. It will be approved very soon. We put exact information on the changelog. We guarantee it. But humans can make mistakes. If there is any issue with the changelog, let us know and we will fix it.

Unfortunately, JoomShaper haven't yet fixed ANY of the bugs which make EasyStore 3.0 unusable in a production website!

I have discussed your issues with my teammates. None of the issues are major issues. Few of the issues are already solved. If you still face issues, then we are here to help.

I hope that we will be respectful in our communication.

Best regards

0
SC
Stuart Clark
Accepted Answer
4 hours ago #234232

Hello Ofi Khan

With due respect, your response is disrespectful. We have submitted the CVEs to Joomla! Security Team. It will be approved very soon. We put exact information on the changelog. We guarantee it. But humans can make mistakes. If there is any issue with the changelog, let us know and we will fix it.

I'm sorry, but recent history has shown us that many JoomShaper products have included MANY security holes, a lot of which haven't been admitted to or even referenced in changelogs. The whole debacle with SP Page Builder, over numerous releases backs this up.

SECURITY HAS NOT HAD THE FOCUS IT DESERVES

I have discussed your issues with my teammates. None of the issues are major issues. Few of the issues are already solved. If you still face issues, then we are here to help.

I, and other customers, have been asking for fixes for OVER 2 YEARS! To hear you say that "none of the issues are major" just shows a complete disregard for your customers needs and backs up the feeling that JoomShaper are not interested in actually supporting customers!

IF JOOMSHAPER ARE INCAPABLE OF RESOLVING BUGS WHICH HAVE EXISTED FOR OVER 2 YEARS, EASYSTORE IS NOT FIT FOR PURPOSE AND SO YOU NEED TO REFUND EVERY CUSTOMER!

I hope that YOU will be respectful in your communication with customers!

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 4 hours ago #234238

We take security issues seriously and fixing all the concerns as soon as possible. There are differences in breaking issues or bugs and customer requirements or feature requests. We cannot satisfy all your requirements. The management also have some decision power.

IF JOOMSHAPER ARE INCAPABLE OF RESOLVING BUGS

Please do not label it like this. If your requirements are not fulfilled, then consider this: It is not getting much attention or not enough requests. Some of the issues are requested only by you. We have to check every pros and cons and alignment of the product with our vision. After that we decide to include or not include the feature.

SO YOU NEED TO REFUND EVERY CUSTOMER!

Not every customer asks for a refund. Those who asked, we have given according to our refund policy.

0
SC
Stuart Clark
Accepted Answer
3 hours ago #234241

Rather than trying to tell customers (me) that they are either wrong or that their issues do not matter, which is what you have said above - WHY NOT consider actually engaging with your customers to see what they really want, rather than what you THINK they want???

I point you to this thread - https://www.joomshaper.com/forum/question/42223 - where you have REPEATEDLY REFUSED to engage by publishing a roadmap for EasyStore.

I point you to this thread - https://www.joomshaper.com/forum/question/34627 - which shows 2 YEAR OLD BUGS which have yet to be resolved. This thread also shows a FAILED COMMITMENT TO PUBLISH A ROADMAP FOR EASYSTORE

I point you to this thread - https://www.joomshaper.com/forum/question/33814 - in which YOU made various commitments to ensure bugs got fixed and requested features added - you've failed in a lot of cases to implement those commitments!

SO, once again - please be respectful in your communication with customers, rather than trying to attack them for pointing out what HASN'T been provided, as previously promised!

0