Privilege Escalation in Joomla Extension by JoomShaper
CVE-2026-78078

8.9HIGH

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-78078?

A vulnerability has been identified in the Helix Ultimate Joomla extension from JoomShaper, which allows attackers to bypass file upload restrictions through content spoofing. This flaw arises due to earlier versions only validating file extensions and size parameters, permitting non-image files to be uploaded after renaming them to appear as valid raster formats. The latest patch implements strict MIME type verification and adds GD binary raster decoding to ensure that only legitimate image files are accepted, thereby preventing the upload of invalid or malformed images.

Affected Version(s)

Helix Ultimate extension for Joomla 1.0-2.2.9

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.