VYPR

Helix Ultimate

by Joomla

CVEs (7)

  • CVE-2026-78078HigAug 31, 2026
    risk 0.58cvss epss 0.00

    Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict…

  • CVE-2026-78077HigAug 31, 2026
    risk 0.56cvss epss 0.00

    Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual…

  • CVE-2026-78079MedAug 31, 2026
    risk 0.34cvss epss 0.00

    Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.

  • CVE-2026-78076MedAug 31, 2026
    risk 0.33cvss epss 0.00

    Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or…

  • CVE-2026-78075MedAug 31, 2026
    risk 0.33cvss epss 0.00

    Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image…

  • CVE-2026-57830CriJul 13, 2026
    risk 0.00cvss 9.1epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

  • CVE-2026-57829MedJul 13, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.