Joomla 扩展 - joomshaper.com - Helix Ultimate 版本低于 2.2.10 中通过 Base64 返回参数实现开放重定向 - 返回重定向参数接受任意 Base64 字符串,且未通过 验证解析后的目标是否为内部站点 URL。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| joomshaper.com | Helix Ultimate extension for Joomla | 1.0-2.2.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78078 | 8.9 HIGH | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in |
| CVE-2026-78077 | 8.6 HIGH | Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout |
| CVE-2026-78076 | 5.1 MEDIUM | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaM |
| CVE-2026-78075 | 5.1 MEDIUM | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deleti |
No comments yet