ZeroHour

CVE-2026-78078

large

Privileged File Upload Bypass via Content Spoofing in JoomShaper Helix Ultimate

CVSS 4.0
8.9 high
EPSS
<1%p17
Published
()
Modified
AI analysis

Helix Ultimate, JoomShaper's Joomla template framework, previously validated image uploads using only the file extension and basic size checks, so non-image files renamed with raster image extensions (content spoofing) could be uploaded past validation (CWE-434). The flaw requires an attacker to already hold high privileges on the Joomla site, such as administrator-level access, making it primarily a post-compromise escalation path rather than an initial-entry vector. Once accepted, a disguised file is stored and served as an image, and the 8.9 CVSS 4.0 score reflects potentially high impact on the site and connected systems where such files may be executed or consumed, though exploitation success can depend on site-specific conditions. All Joomla sites running Helix Ultimate versions below 2.2.10 are affected; version 2.2.10 adds strict MIME verification and GD-based raster decoding (imagecreatefromstring) that reject invalid or malformed images fail-closed. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and EPSS currently estimates only a 0.3% chance of exploitation within 30 days.

What to do: Update Helix Ultimate to version 2.2.10 or later. Audit media and upload directories for files bearing image extensions that are not actually valid images (e.g., by running MIME/file-type checks), and review administrator account security, since exploitation requires high privileges.

Affected
JoomShaper (joomshaper.com) Helix Ultimate (Joomla template framework)< 2.2.10 (fixed in 2.2.10)
Estimated exposure
largelikely hundreds of thousands of Joomla sites — Helix Ultimate is JoomShaper's flagship and one of the most widely deployed Joomla template frameworks, and Joomla's overall installed base is on the order of 1-2 million sites, suggesting a six-figure deployment footprint, though no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster decoding (imagecreatefromstring) to reject invalid/malformed images fail-closed.

Ecosystems
Joomla
Weakness
CWE-434
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.