cve-2026-49049
HIGH CVSS 7.5 circl_kev
Description
Affected: JoomShaper / Helix3 extension for Joomla | Description: Helix3 plugin for Joomla exposes an ajax handler task that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters. | Patched since: 2026/06/29 | Exploitation type: unknown | CWEs: CWE-284 | Origin source: CNW | Notes: https://www.joomshaper.com/forum/question/45671
Timeline
- Published
- Last Modified
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 7.5,
"datePublished": "",
"dateUpdated": "",
"description": "Affected: JoomShaper / Helix3 extension for Joomla | Description: Helix3 plugin for Joomla exposes an ajax handler task that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters. | Patched since: 2026/06/29 | Exploitation type: unknown | CWEs: CWE-284 | Origin source: CNW | Notes: https://www.joomshaper.com/forum/question/45671",
"dueDate": "",
"exploited": true,
"id": "CVE-2026-49049",
"kev_catalogs": [
"circl"
],
"knownRansomwareCampaignUse": "",
"product": "Helix3 extension for Joomla",
"severity": "HIGH",
"source": "circl_kev",
"title": "CVE-2026-49049",
"vendor": "JoomShaper"
}
Enrichment data
Aggregated bundle (all enrichments)