Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

JoomShaper Joomla 3 extensions face actively exploited flaws

mySites.guru has reported three security flaws affecting JoomShaper extensions on Joomla 3, including a critical SP Page Builder vulnerability that has been actively exploited.

The affected products are SP Page Builder, Helix3 and Helix Ultimate running on Joomla 3. mySites.guru said the vendor’s original fixes were available only for newer Joomla versions before JoomShaper released separate Joomla 3 patches on 15 July 2026.

  • SP Page Builder: unauthenticated icon upload leading to remote code execution, CVE-2026-48908, CVSS 10.0. The flaw has been actively exploited.
  • Helix3: unauthenticated file writing and deletion through com_ajax, CVE-2026-49049, CVSS 7.5. mySites.guru linked it to the “Hacked by AntonKill” defacement wave.
  • Helix Ultimate: unauthenticated menu modification leading to stored cross-site scripting. No CVE was assigned; the severity is High.

The previously listed fixed versions were SP Page Builder 6.6.2, Helix3 3.1.1 and Helix Ultimate 2.2.7, all requiring Joomla 4 or newer. Administrators should apply JoomShaper’s Joomla 3 patches where they install, plan migration from Joomla 3, and treat already compromised sites separately because patching does not remove an existing breach.

Originally reported by mySites.guru.