Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-49049?

CVE-2026-49049 is a vulnerability classified as Improper Access Control, affecting Helix3 extension for Joomla (affected versions: 1.0-3.1.1). This vulnerability is rated High, with a CVSS score of 7.5. Current sources do not report this vulnerability as exploited.

Analyzing data...

Overview

Original source data

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Affected products and scope

Analyzing data...

Technical details

Analyzing data...

Exploitability

Analyzing data...

Technical impact

Analyzing data...

Business impact

Analyzing data...

Remediation

Analyzing data...

Detection

Analyzing data...
Sources (6)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan