Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

Helix3 Template security vulnerabilities

mySites.guru tracks 1 vulnerability in Helix3 Template (shaper_helix3), covering 1 CVE. Every connected Joomla site is checked against it on each audit.

Is my site affected?

Your site is affected if it runs Helix3 Template in this range:

  • before 3.1.2
Latest safe version
3.1.2 or later. No rule we check matches that release or any newer one.
What to do
Update Helix3 Template to 3.1.2 or later from the vendor, then confirm the installed version on the Joomla administrator's Extensions: Manage screen.

Every Helix3 Template vulnerability we track

Newest first. CVSS is the score published in each CVE record, where it has one; the severity column is the rating our check uses.

CVEAffected versionsFixed inSeverityAdded
CVE-2026-49049CVSS 7.5before 3.1.23.1.2Critical2026-06-29

What we check for

CriticalCVE-2026-490492026-06-29

Helix3 Template (shaper_helix3) below 3.1.2 - Unauthenticated File Write/Delete via com_ajax (RCE, CVE-2026-49049)

The Helix3 template framework's com_ajax plugin handler (plugins/ajax/helix3/helix3.php, onAjaxHelix3) performs a file write/delete reachable without authentication: no authorise() or session-token gate on a guest com_ajax request. Fixed in Helix3 3.1.1 (JoomShaper security release, 29 Jun 2026); the patched build closes multiple unauthenticated vectors in the handler, not only the reported actions. CVE pending (credited to Phil Taylor, Blue Flame Digital Solutions). Update to 3.1.1 or later. Affected 1.0-3.1.1 (CVE-2026-49049); fixed in Helix3 3.1.2.

Affected versions: < 3.1.2

Full advisory: www.joomshaper.com

Timeline

  1. 29 June 2026Check added for CVE-2026-49049 (before 3.1.2)
  2. 29 June 2026CVE-2026-49049 record published
  3. 29 June 2026We published: Helix3 Shipped a Critical Fix as "Security Update"
  4. 8 July 2026We published: The Helix3 Defacement Lives in Your Database, Not Your Files

What we have written about Helix3 Template

References

Each CVE page above links its official cve.org record and its NVD entry.

Helix3 Template vulnerability questions

Which versions of Helix3 Template are vulnerable?
mySites.guru tracks one vulnerability in Helix3 Template (shaper_helix3). A site is affected if its installed version is in this range: before 3.1.2.
What is the latest safe version of Helix3 Template?
3.1.2. Every vulnerability tracked here is fixed by 3.1.2, and no rule we check matches that release or any later one.
How do I check which version of Helix3 Template my Joomla site runs?
The installed version is listed on the Joomla administrator's Extensions: Manage screen; search it for shaper_helix3. mySites.guru reads the installed version on every audit of a connected site and checks it against this rule.

Running Helix3 Template on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

CVE identifiers: CVE-2026-49049. Rules current as of 5 October 2026.