ZeroHour

CVE-2026-49049

CVSS 3.1
7.5 high
EPSS
<1%p60
Published
()
Modified
Description

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Vendors
ollyo
Products
helix3
Ecosystems
Joomla
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.