CVE-2026-49049
EUVD-2026-4012229.06.2026, 15:16
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ollyo | helix3 | 1.0 ≤ 𝑥 ≤ 3.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References