{
  "cvss": 7.5,
  "datePublished": "",
  "dateUpdated": "",
  "description": "Affected: JoomShaper / Helix3 extension for Joomla | Description: Helix3 plugin for Joomla exposes an ajax handler task that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters. | Patched since: 2026/06/29 | Exploitation type: unknown | CWEs: CWE-284 | Origin source: CNW | Notes: https://www.joomshaper.com/forum/question/45671",
  "dueDate": "",
  "exploited": true,
  "id": "CVE-2026-49049",
  "kev_catalogs": [
    "circl"
  ],
  "knownRansomwareCampaignUse": "",
  "product": "Helix3 extension for Joomla",
  "severity": "HIGH",
  "source": "circl_kev",
  "title": "CVE-2026-49049",
  "vendor": "JoomShaper"
}