High severity7.5NVD Advisory· Published Jun 29, 2026· Updated Jun 30, 2026
CVE-2026-49049
CVE-2026-49049
Description
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
Affected products
2Patches
Vulnerability mechanics
References
1- www.joomshaper.comnvdProduct
News mentions
0No linked articles in our index yet.