CVE-2026-57830: Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7
Published Jul 13, 2026
·Updated
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
Affected Software
2 affected components
JoomShaper Helix Ultimate<2.2.7
Ollyo Helix Ultimate Joomla\!>=1.0<=2.2.6
Event History
Jul 13, 2026
CVE Published
via MITRE·07:30 AM
Data Sourced
via MITRE·07:30 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57830?
CVE-2026-57830 has a severity rating of high at 8.8 according to the CVSS v4.0.
2
How do I fix CVE-2026-57830?
To fix CVE-2026-57830, update the JoomShaper Helix Ultimate extension to version 2.2.7 or later.
3
What type of vulnerability is CVE-2026-57830?
CVE-2026-57830 is an unauthenticated arbitrary file deletion vulnerability in the Helix Ultimate Joomla extension.
4
Who is affected by CVE-2026-57830?
Users of the JoomShaper Helix Ultimate extension below version 2.2.7 are affected by CVE-2026-57830.
5
What is the impact of CVE-2026-57830?
CVE-2026-57830 can allow unauthorized users to delete arbitrary files on a server running the vulnerable extension.