← Back to browse · API

CVE-2026-49049

Severity
HIGH
CVSS
7.5
EPSS
0.28307
Risk score
39.91
CISA KEV
No
PoC
Yes
Published
2026-06-29
Modified
2026-08-12
First seen
2026-08-07
Aliases
EUVD-2026-40122, GHSA-XR7R-292V-JXG8
Products
joomshaper.com:Helix3 extension for Joomla 1.0-3.1.1
Sources
github fc4a7263df422bfc6d747c03|CVE-2026-49049
euvd EUVD-2026-40122

Description

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

References