{"cvss":7.5,"datePublished":"","dateUpdated":"","description":"Affected: JoomShaper / Helix3 extension for Joomla | Description: Helix3 plugin for Joomla exposes an ajax handler task that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters. | Patched since: 2026/06/29 | Exploitation type: unknown | CWEs: CWE-284 | Origin source: CNW | Notes: https://www.joomshaper.com/forum/question/45671","dueDate":"","exploited":true,"id":"CVE-2026-49049","kev_catalogs":["circl"],"knownRansomwareCampaignUse":"","product":"Helix3 extension for Joomla","severity":"HIGH","source":"circl_kev","title":"CVE-2026-49049","vendor":"JoomShaper"}