CVE-2026-78078
largePrivileged File Upload Bypass via Content Spoofing in JoomShaper Helix Ultimate
Helix Ultimate, JoomShaper's Joomla template framework, previously validated image uploads using only the file extension and basic size checks, so non-image files renamed with raster image extensions (content spoofing) could be uploaded past validation (CWE-434). The flaw requires an attacker to already hold high privileges on the Joomla site, such as administrator-level access, making it primarily a post-compromise escalation path rather than an initial-entry vector. Once accepted, a disguised file is stored and served as an image, and the 8.9 CVSS 4.0 score reflects potentially high impact on the site and connected systems where such files may be executed or consumed, though exploitation success can depend on site-specific conditions. All Joomla sites running Helix Ultimate versions below 2.2.10 are affected; version 2.2.10 adds strict MIME verification and GD-based raster decoding (imagecreatefromstring) that reject invalid or malformed images fail-closed. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and EPSS currently estimates only a 0.3% chance of exploitation within 30 days.
What to do: Update Helix Ultimate to version 2.2.10 or later. Audit media and upload directories for files bearing image extensions that are not actually valid images (e.g., by running MIME/file-type checks), and review administrator account security, since exploitation requires high privileges.
| JoomShaper (joomshaper.com) Helix Ultimate (Joomla template framework) | < 2.2.10 (fixed in 2.2.10) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster decoding (imagecreatefromstring) to reject invalid/malformed images fail-closed.
- Ecosystems
- Joomla
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.