VYPR
Vendor

Ollyo

Products
3
CVEs
4
Across products
4
Status
Private

Products

3

Recent CVEs

4
  • CVE-2026-48908CriKEVJun 20, 2026
    risk 0.83cvss 9.8epss 0.88

    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

  • CVE-2026-49049HigJun 29, 2026
    risk 0.01cvss 7.5epss 0.18

    The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

  • CVE-2026-57830CriJul 13, 2026
    risk 0.00cvss 9.1epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

  • CVE-2026-57829MedJul 13, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.