HTProtect.org
HTProtect HTProtect JOOMLA SECURITY
htprotect.org Vulnerabilities & update guides
New htprotect.app - Centralized Joomla Site Management for Multiple Websites
Independent information site

Joomla security vulnerabilities – current & clearly explained

htprotect.org collects current, critical security vulnerabilities of popular Joomla extensions and frameworks – factual, free and with step-by-step guides that are easy to follow even for beginners. The goal: warn those affected quickly and help them close the gaps.

10 current flaws Neutral & free Sources linked
What this is – and what it is not
This site is neutral and informative, not promotional. It summarises publicly available vendor and research information and links the original sources. The only exception is the clearly marked section on the protection extension HTProtect. In all cases: the most effective measure is applying the official updates promptly.

Is a website affected? Check now.

Free scanner: checks a domain with evidence for malicious redirects (spam/phishing/jmtouch), the Japanese Keyword Hack (cloaking) and injected code.

Start the Spam/Hack Check
Security status

Current security status

Ten current flaws rated as critical. Check the installed versions – details and guides per entry.

  • Helix3 Framework
    Several unauthenticated file & upload flaws in the AJAX plugin.
    Secure with: Helix3 3.1.2 or newer · Download · actively exploited
    Details
  • Helix Ultimate
    Unauthenticated write access to menus (stored XSS) and more in the AJAX handler; update now.
    Secure with: Helix Ultimate 2.2.8 or newer · Download
    Details
  • Astroid Framework
    Unauthenticated upload → code execution; exploited in the wild.
    Secure with: Astroid 3.3.13 or newer · Download · CVE-2026-21628 · actively exploited
    Details
  • Tassos / Novarain
    Unauthenticated AJAX flaw in the framework behind many extensions; CVSS 9.5.
    Secure with: Tassos Framework 6.0.62 or higher · Download · CVE-2026-21627
    Details
  • JCE Editor
    Unauthenticated upload; actively exploited for web shells.
    Secure with: JCE 2.9.99.5 – better 2.9.99.6 · Download · actively exploited
    Details
  • iCagenda
    Missing login check in the event form → upload without authentication.
    Secure with: iCagenda 4.0.8 (Joomla 3: 3.9.15) · Download · CVE-2026-48939
    Details
  • SP Page Builder
    Zero-day upload → RCE without login; actively exploited.
    Secure with: SP Page Builder 6.6.2 (emergency update) · Download · actively exploited
    Details
  • Balbooa Forms
    Unauthenticated file upload in the form front end → code execution; exploited in the wild.
    Secure with: Balbooa Forms 2.4.1 or newer · Download · CVE-2026-56291 · actively exploited
    Details
  • AcyMailing
    Unauthenticated SQL injection; anonymous reading of the database incl. password hashes.
    Secure with: AcyMailing 10.11.1 or newer · Download · CVE-2026-56292
    Details
  • RSFiles!
    Unauthenticated file upload in the front end → code execution; update now.
    Secure with: RSFiles! 1.17.12 or newer · Download
    Details
The flaws in detail

Quick overview & entry point

Each flaw briefly outlined – one click leads to the detailed, beginner-friendly guide.

Helix3 Framework
JoomShaper
Criticalactively exploited

Several serious flaws were disclosed in the AJAX plugin of JoomShaper's Helix3 template framework – including writing and deleting files and uploading PHP code without logging in. All versions before 3.1.1 are affected; the fix is available via the normal Joomla updater (currently 3.1.2). Note: Helix3 is not the same as the newer Helix Ultimate.

Helix Ultimate
JoomShaper
Critical

JoomShaper's Helix Ultimate template framework runs an AJAX handler even for visitors who aren't logged in. Before version 2.2.7, several actions ran without any login or permission check – the most serious being write access to the menus, which allows malicious script to be planted permanently (stored XSS). There is also a path-traversal file deletion, an open redirect and an unprotected template export. All versions before 2.2.7 are affected; the fix is available via the Joomla updater (currently 2.2.8). Note: Helix Ultimate is not the same as Helix3.

Astroid Framework
TemPlaza
Criticalactively exploited

In the widely used Astroid Framework, a critical flaw allows files to be uploaded without any authentication – and, in the worst case, code execution (RCE). Versions 2.0.0 to 3.3.10 are affected; fixed from 3.3.11, with 3.3.13 or newer recommended (CVE-2026-21628). Already-compromised sites often show injected plugins such as "BLPayload" or "JCachePro".

Tassos / Novarain
tassos.gr
CriticalExploit available

The Tassos Framework (formerly Novarain) sits unnoticed inside many popular extensions such as Convert Forms or EngageBox. Unauthenticated AJAX calls allow file and database access – rated critical at CVSS 9.5, with a public exploit tool available (CVE-2026-21627). It is enough to update any one Tassos extension: the framework is automatically raised to a secure version (6.0.62+).

JCE Editor
JoomlaContentEditor
Criticalactively exploited

JCE is one of the most-used editors for Joomla. Insufficient access control allowed unauthenticated attackers to upload editor profiles and, through them, arbitrary files – and the flaw is already being actively exploited to plant web shells. All versions before 2.9.99.5 are affected (Free and Pro), regardless of whether registration is enabled. Secure is 2.9.99.5, better the follow-up 2.9.99.6.

iCagenda
Event calendar
Critical

iCagenda is a popular event calendar for Joomla. The form for submitting events lacked a real login check – so even unauthenticated attackers could upload files, even when the form was supposedly restricted to registered users. On Joomla 6 (6.0.0–6.1.1) this turns into a critical file-upload flaw (CVE-2026-48939). Affected is iCagenda 3.2.1 to 4.0.7; fixed in 4.0.8 (on Joomla 3 in 3.9.15).

SP Page Builder
JoomShaper
Criticalactively exploited

SP Page Builder is one of the most-used page builders for Joomla. A zero-day flaw in the custom-icon upload function checked neither login nor file type, allowing code execution (RCE) without a login. The entire 6.x series up to and including 6.6.1 is affected; the emergency update 6.6.2 closes the hole. It is already being actively exploited and leaves behind hidden super-users and backdoors.

Balbooa Forms
Balbooa
Criticalactively exploited

Balbooa Forms is a widely used form builder for Joomla. Its form file-upload accepts files without any login – and without checking a security token or the file type. That lets an attacker drop an executable PHP file into a publicly reachable folder and run it (remote code execution). All versions up to 2.4.0 are affected; the 2.4.1 update closes the hole (CVE-2026-56291). The flaw is already being exploited in the wild.

AcyMailing
Acyba
Critical

AcyMailing is a widely used newsletter component for Joomla. A publicly reachable front-end endpoint put request parameters into a database query unchecked. That let an unauthenticated visitor read any table – including user accounts with password hashes and site content (SQL injection). Versions 6.0.0 to 10.11.0 are affected; fixed from 10.11.1 (CVE-2026-56292).

RSFiles!
RSJoomla!
Critical

RSFiles! is a file and download manager for Joomla. A front-end upload function could be triggered without logging in and checked neither a security token nor the file type. That lets a PHP file reach a publicly accessible directory and run there (remote code execution). All versions up to 1.17.11 are affected; the 1.17.12 update closes the hole.

Basics

How to update a Joomla extension safely

Almost all of the flaws described here are closed the same way – via the Joomla update center. This general guide is for beginners:

First: make a backup
Back up files and database before changing anything – e.g. with Akeeba Backup or via your host. That way you can roll back if there is a problem.
  1. Log in to the back end

    Open the Joomla administrator (your domain with /administrator appended) and log in.

  2. Open the Update center

    Go to SystemUpdateExtensions and click Check for updates.

  3. Update the extension

    Select the affected extension from the list and click Update. Joomla downloads and installs the new version automatically.

  4. Verify the version

    Then check the installed version number (component or ExtensionsManage) and compare it with the "secure version" on the relevant detail page.

  5. If a compromise is suspected: clean up

    An update closes the hole but does not remove malware already injected. If anything looks off, have the site professionally cleaned – e.g. via a specialist from the Joomla Service Providers Directory – and change all passwords.

No update shown?
First update Joomla itself and check under SystemUpdateUpdate sites whether the source is enabled. Otherwise download the package from the vendor and install it via ExtensionsManageInstall.
Protection extension
HTProtect

Many of the flaws listed here follow the same pattern: unauthenticated file upload. This is exactly where HTProtect comes in – an additional layer of protection for Joomla that at the same time helps keep extensions up to date.

One-click hardeningJoomla security extensionby Website-Bereinigung.de
Real-time protection (WAF)
Blocks exploit calls even in the POST body that a plain .htaccess never sees.
Exploit shield & live signatures
New signatures are loaded automatically – zero-days are covered promptly.
Upload folder hardening
Prevents execution of uploaded PHP files – exactly the entry point of these flaws.
Monitoring & email alerts
A watchdog checks files, super-user accounts, defacement & a watch list and reports anomalies.
Site scan & vulnerable extensions
Malware scanner with community-driven signatures – finds injected code and back doors (web shells) and removes them.
Auto-updates with a safety net
Updates Joomla extensions automatically – with a file & database backup and automatic rollback if an update breaks something.

Note: the most effective measure remains keeping extensions up to date – and HTProtect can take care of exactly that automatically, including a backup. In the window until an update is applied, it additionally lowers the risk (WAF, .htaccess hardening) and reports anomalies.

Or without a file upload, straight via “Install from URL” (Extensions › Manage › Install › Install from URL):

Supporters

Supporters of this site

htprotect.org is a free, vendor-independent information service. It is supported by:

Host & community
FC-Hosting

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.

fc-hosting.de
Initiator & operator
Website-Bereinigung.de

Specialised in cleaning, maintaining and securing Joomla and WordPress websites.

website-bereinigung.de

Support this project

You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.

Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.

Support HTProtect now
Bauschild & Service

Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.

bauschildundservice.de
IT Specialista

Professional IT support from Czechia – Windows management, domain administration and web hosting.

defendersoft.cz
onlineweg.de

Travel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.

onlineweg.de
Criadero

Creative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.

criadero.de
Jahn EDV-Dienst GmbH

IT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.

jahnedv.de
IsariConsult

Information-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.

isari-consult.de