Ollyo: community verdicts
4 notable / known-exploited Ollyo CVEs the community has triaged.
- CVE-2026-48908CRIT 9.8KEVEPSS 88%
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- CVE-2026-57830CRIT 9.1Real · low riskEPSS 0%
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
- CVE-2026-49049HIGH 7.5Real · low riskEPSS 0%
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
- CVE-2026-57829MED 6.1EPSS 0%
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.