Several serious flaws were disclosed in the AJAX plugin of JoomShaper's Helix3 template framework – including writing and deleting files and uploading PHP code without logging in. All versions before 3.1.1 are affected; the fix is available via the normal Joomla updater (currently 3.1.2). Note: Helix3 is not the same as the newer Helix Ultimate.
Joomla security vulnerabilities – current & clearly explained
htprotect.org collects current, critical security vulnerabilities of popular Joomla extensions and frameworks – factual, free and with step-by-step guides that are easy to follow even for beginners. The goal: warn those affected quickly and help them close the gaps.
Current security status
Ten current flaws rated as critical. Check the installed versions – details and guides per entry.
-
Helix3 FrameworkDetailsSeveral unauthenticated file & upload flaws in the AJAX plugin.
-
Helix UltimateDetailsUnauthenticated write access to menus (stored XSS) and more in the AJAX handler; update now.
-
Astroid FrameworkDetailsUnauthenticated upload → code execution; exploited in the wild.
-
Tassos / NovarainDetailsUnauthenticated AJAX flaw in the framework behind many extensions; CVSS 9.5.
-
JCE EditorDetailsUnauthenticated upload; actively exploited for web shells.
-
iCagendaDetailsMissing login check in the event form → upload without authentication.
-
SP Page BuilderDetailsZero-day upload → RCE without login; actively exploited.
-
Balbooa FormsDetailsUnauthenticated file upload in the form front end → code execution; exploited in the wild.
-
AcyMailingDetailsUnauthenticated SQL injection; anonymous reading of the database incl. password hashes.
-
RSFiles!DetailsUnauthenticated file upload in the front end → code execution; update now.
Quick overview & entry point
Each flaw briefly outlined – one click leads to the detailed, beginner-friendly guide.
JoomShaper's Helix Ultimate template framework runs an AJAX handler even for visitors who aren't logged in. Before version 2.2.7, several actions ran without any login or permission check – the most serious being write access to the menus, which allows malicious script to be planted permanently (stored XSS). There is also a path-traversal file deletion, an open redirect and an unprotected template export. All versions before 2.2.7 are affected; the fix is available via the Joomla updater (currently 2.2.8). Note: Helix Ultimate is not the same as Helix3.
In the widely used Astroid Framework, a critical flaw allows files to be uploaded without any authentication – and, in the worst case, code execution (RCE). Versions 2.0.0 to 3.3.10 are affected; fixed from 3.3.11, with 3.3.13 or newer recommended (CVE-2026-21628). Already-compromised sites often show injected plugins such as "BLPayload" or "JCachePro".
The Tassos Framework (formerly Novarain) sits unnoticed inside many popular extensions such as Convert Forms or EngageBox. Unauthenticated AJAX calls allow file and database access – rated critical at CVSS 9.5, with a public exploit tool available (CVE-2026-21627). It is enough to update any one Tassos extension: the framework is automatically raised to a secure version (6.0.62+).
JCE is one of the most-used editors for Joomla. Insufficient access control allowed unauthenticated attackers to upload editor profiles and, through them, arbitrary files – and the flaw is already being actively exploited to plant web shells. All versions before 2.9.99.5 are affected (Free and Pro), regardless of whether registration is enabled. Secure is 2.9.99.5, better the follow-up 2.9.99.6.
iCagenda is a popular event calendar for Joomla. The form for submitting events lacked a real login check – so even unauthenticated attackers could upload files, even when the form was supposedly restricted to registered users. On Joomla 6 (6.0.0–6.1.1) this turns into a critical file-upload flaw (CVE-2026-48939). Affected is iCagenda 3.2.1 to 4.0.7; fixed in 4.0.8 (on Joomla 3 in 3.9.15).
SP Page Builder is one of the most-used page builders for Joomla. A zero-day flaw in the custom-icon upload function checked neither login nor file type, allowing code execution (RCE) without a login. The entire 6.x series up to and including 6.6.1 is affected; the emergency update 6.6.2 closes the hole. It is already being actively exploited and leaves behind hidden super-users and backdoors.
Balbooa Forms is a widely used form builder for Joomla. Its form file-upload accepts files without any login – and without checking a security token or the file type. That lets an attacker drop an executable PHP file into a publicly reachable folder and run it (remote code execution). All versions up to 2.4.0 are affected; the 2.4.1 update closes the hole (CVE-2026-56291). The flaw is already being exploited in the wild.
AcyMailing is a widely used newsletter component for Joomla. A publicly reachable front-end endpoint put request parameters into a database query unchecked. That let an unauthenticated visitor read any table – including user accounts with password hashes and site content (SQL injection). Versions 6.0.0 to 10.11.0 are affected; fixed from 10.11.1 (CVE-2026-56292).
RSFiles! is a file and download manager for Joomla. A front-end upload function could be triggered without logging in and checked neither a security token nor the file type. That lets a PHP file reach a publicly accessible directory and run there (remote code execution). All versions up to 1.17.11 are affected; the 1.17.12 update closes the hole.
How to update a Joomla extension safely
Almost all of the flaws described here are closed the same way – via the Joomla update center. This general guide is for beginners:
- Log in to the back end
Open the Joomla administrator (your domain with
/administratorappended) and log in. - Open the Update center
Go to System›Update›Extensions and click Check for updates.
- Update the extension
Select the affected extension from the list and click Update. Joomla downloads and installs the new version automatically.
- Verify the version
Then check the installed version number (component or Extensions›Manage) and compare it with the "secure version" on the relevant detail page.
- If a compromise is suspected: clean up
An update closes the hole but does not remove malware already injected. If anything looks off, have the site professionally cleaned – e.g. via a specialist from the Joomla Service Providers Directory – and change all passwords.
Many of the flaws listed here follow the same pattern: unauthenticated file upload. This is exactly where HTProtect comes in – an additional layer of protection for Joomla that at the same time helps keep extensions up to date.
.htaccess never sees.Note: the most effective measure remains keeping extensions up to date – and HTProtect can take care of exactly that automatically, including a backup. In the window until an update is applied, it additionally lowers the risk (WAF, .htaccess hardening) and reports anomalies.
Or without a file upload, straight via “Install from URL” (Extensions › Manage › Install › Install from URL):
Supporters of this site
htprotect.org is a free, vendor-independent information service. It is supported by:

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.
fc-hosting.deSpecialised in cleaning, maintaining and securing Joomla and WordPress websites.
website-bereinigung.deSupport this project
You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.
Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.
Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.
bauschildundservice.deProfessional IT support from Czechia – Windows management, domain administration and web hosting.
defendersoft.czTravel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.
onlineweg.deCreative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.
criadero.deIT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.
jahnedv.deInformation-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.
isari-consult.de