CVE-2026-49049
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
- Published
- Jun 29, 2026
- Updated
- Aug 12, 2026
- Assigning CNA
- Joomla
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NLow · next 30 days
- Percentile
- 60.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
Sources
7Technical analysis and Proof of Concept (PoC) for CVE-2026-49049, an unauthenticated arbitrary file write vulnerability in JoomShaper Helix3 for Joomla, including exploitation vectors and mitigation guidance.
- CVE-2026-49049Scanner
CVE-2026-49049 Helix3 (JoomShaper) Joomla Unauthenticated AJAX RCE Scanner
- CVE-2026-49049Scanner
Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed and raw PHP payloads.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.