By vendor
Ollyo vulnerabilities
Known CVEs affecting Ollyo products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-49049HIGH 7.5
An unauthenticated security flaw in the Helix3 plugin for Joomla allows attackers to delete files, write JSON files, and modify template settings without needing user credentials. The vulnerability exists in an exposed AJAX handler that lacks proper access controls, making it trivial for any internet-connected attacker to exploit remotely. This poses an immediate risk to site integrity and functionality.