Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

JoomShaper releases security patches for Joomla 3 extensions

JoomShaper has released Joomla 3 security updates for Helix Ultimate, Helix3 and SP Page Builder, reversing its recent decision to stop providing patches for the end-of-life platform.

The fixes address multiple security issues, including unauthenticated actions, upload flaws, traversal, open redirects and stored cross-site scripting. mySites.guru, which published the research, identifies CVE-2026-49049 in Helix3 and CVE-2026-48908 in SP Page Builder. The latter is rated CVSS 10.0.

  • Helix Ultimate: the Joomla 3 patch uses the 2.1.4-j3sec baseline and supports versions from 2.1.0 through that release.
  • Helix3: security patch v1.0.0 updates the extension and template to 3.1.2.
  • SP Page Builder: an existing manual security fix is now installable through Joomla’s extension installer; the source does not specify a fixed version.

The report says the vulnerabilities were exploited in the wild, including defacements and the creation of hidden Super Administrators. Administrators should apply the vendor patches, check sites for compromise, and note that Helix Ultimate versions below 2.1.0 cannot use its patch. Joomla 3 itself remains unsupported, so migration to a supported Joomla release should continue.

Originally reported by mySites.guru.