Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-48908 2 Joomshaper.net, Ollyo 2 Sp Page Builder Extension For Joomla, Sp Page Builder 2026-07-07 9.8 Critical
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
CVE-2026-49049 2 Joomshaper, Ollyo 2 Helix3 Extension For Joomla, Helix3 2026-07-01 7.5 High
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.