Unrated severityNVD Advisory· Published Jun 29, 2026· Updated Jul 5, 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
CVE-2026-49049
Description
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
Affected products
1Patches
Vulnerability mechanics
References
1- www.joomshaper.commitreproduct
News mentions
0No linked articles in our index yet.