← Back

Ollyo

ollyo

4 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Helix3
helix3

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ollyo
1Helix Ultimate
Jul 14, 2026
Jul 13, 2026
8.8 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
1Ollyo
1Helix Ultimate
Jul 14, 2026
Jul 13, 2026
8.7 HIGH· v4
6.1 MEDIUM· v3
N/A· v2
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
1Ollyo
1Helix3
Jun 30, 2026
Jun 29, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
1Ollyo
1Sp Page Builder
Jul 8, 2026
Jun 20, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.