Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57830 1 Ollyo 1 Helix Ultimate 2026-07-23 9.1 Critical
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
CVE-2026-57829 1 Ollyo 1 Helix Ultimate 2026-07-23 6.1 Medium
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
CVE-2026-48908 2 Joomshaper.net, Ollyo 2 Sp Page Builder Extension For Joomla, Sp Page Builder 2026-07-07 9.8 Critical
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
CVE-2026-49049 2 Joomshaper, Ollyo 2 Helix3 Extension For Joomla, Helix3 2026-07-01 7.5 High
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.