VYPR

Helix Ultimate

by JoomShaper

CVEs (2)

  • CVE-2026-78078HigAug 31, 2026
    risk 0.58cvss epss

    Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict…

  • CVE-2026-57829MedJul 13, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.