CVE-2026-49049

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
References
Link Resource
https://www.joomshaper.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:ollyo:helix3:*:*:*:*:*:joomla\!:*:*

History

30 Jun 2026, 17:18

Type Values Removed Values Added
First Time Ollyo
Ollyo helix3
References () https://www.joomshaper.com/ - () https://www.joomshaper.com/ - Product
CPE cpe:2.3:a:ollyo:helix3:*:*:*:*:*:joomla\!:*:*

29 Jun 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

29 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-29 15:16

Updated : 2026-06-30 17:18


NVD link : CVE-2026-49049

Mitre link : CVE-2026-49049

CVE.ORG link : CVE-2026-49049


JSON object : View

Products Affected

ollyo

  • helix3
CWE
CWE-284

Improper Access Control