Open Redirect Vulnerability in Joomla Extension by Joomshaper
CVE-2026-78079
5.3MEDIUM
What is CVE-2026-78079?
An open redirect vulnerability exists in the Helix Ultimate Joomla extension from Joomshaper. This issue allows malicious actors to manipulate return redirect parameters, which can accept arbitrary Base64 encoded strings. The vulnerability arises because the system fails to verify if the resolved target points to an internal site URL. Exploiting this flaw could redirect users to unintended external sites, posing various security risks such as phishing and data theft.
Affected Version(s)
Helix Ultimate extension for Joomla 1.0-2.2.9
