CVE-2026-49049
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedThe Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters. Source description excerpt; complete tracked detail loads below.
NVD published: Jun 29, 2026 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
What is affected
Reportedjoomshaper.com — Helix3 extension for Joomla. Product-level identification only; no affected-version conclusion is available from this field.
NVD published: Jun 29, 2026 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Urgency and basis
ReportedAct · 450.6
Tracker decision tier from the evidence detailed below · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Exploitation evidence
Reportedkev-listed · ENISA exploited-vulnerability catalog
ENISA added: Jul 10, 2026 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
What to do
Not reportedNot reported by tracked sources.
Evidence detail
Loading the full tracker evidence record…