Vulnerabilities (CVE)

Filtered by vendor Ollyo Subscribe
Filtered by product Helix3
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-49049 1 Ollyo 1 Helix3 2026-06-30 N/A 7.5 HIGH
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.