Skip to main content

JoomShaper and Joomla 3

Said stopped, kept shipping

Announced on 9 July 2026 that Joomla 3 would get no security patches regardless of severity, then shipped Joomla 3 security packages for Helix Ultimate, Helix3 and SP Page Builder six days later and kept patching through September.

Joomla extensions covered: Helix Ultimate, Helix3, SP Page Builder. JoomShaper website

What they said

  • “No security patches, regardless of severity”

    Said 9 Jul 2026Read it on their siteChecked 2 Oct 2026

What they did

  1. Joomla 3 security patches ship for Helix Ultimate, Helix3 and SP Page Builder, six days after the no-patches announcement

    Source

  2. Helix Ultimate Joomla 3 patch 1.0.1 released

    Source

  3. Helix Ultimate J3 Security Fixes 1.0.2 backports most of the 2.2.10 security work, under the unchanged version string 2.1.4-j3sec

    Source

  4. Helix Ultimate J3 Security Fixes 1.0.3 closes an authorisation gap mySites.guru reported in 1.0.2

    Source

  5. SP Page Builder Joomla 3 patch 1.0.2 ships alongside 6.9.1; mySites.guru reports two gaps in it the same day

    Source

  6. SP Page Builder Joomla 3 Security Patch 1.0.3 closes the captcha bypass and the incomplete XSS fix

    Source

Known Joomla 3 vulnerabilities

  • High

    SP Page Builder (com_sppagebuilder) 6.8.0 to 6.9.0 - CVE-2026-78375 Author-level SQL Injection (full database read, CVSS 8.6), CVE-2026-79700 and CVE-2026-79701 Unauthenticated Captcha Bypass, plus three authorisation flaws - fixed in 6.9.1

    Affected: ≥ 6.8.0 and < 6.9.1

    CVE-2026-78375, CVE-2026-79700, CVE-2026-79701, CVE-2026-81564, CVE-2026-81565, CVE-2026-81566

  • Critical

    SP Page Builder (com_sppagebuilder) 4.0.0 to 6.6.1 - CVE-2026-48908 (CVSS 10.0) Unauthenticated Arbitrary File Upload (RCE)

    Affected: ≥ 4.0.0 and < 6.6.2

    CVE-2026-48908

  • High

    Helix Ultimate Framework (helixultimate) 2.2.7 to 2.2.9 - Media Upload Bypass, Path Traversal, Broken Access Control and Stored XSS

    Affected: ≥ 2.2.7 and < 2.2.10

    CVE-2026-78075, CVE-2026-78076, CVE-2026-78077, CVE-2026-78078, CVE-2026-78079

  • Unrated

    Helix Ultimate Framework (helixultimate) below 2.1.4-j3sec - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu) - free JoomShaper security patch available

    Affected: < 2.1.4-j3sec

  • High

    Helix Ultimate (shaper_helixultimate) 2.2.7 to 2.2.9 - Media Upload Bypass, Path Traversal, Broken Access Control and Stored XSS

    Affected: ≥ 2.2.7 and < 2.2.10

    CVE-2026-78075, CVE-2026-78076, CVE-2026-78077, CVE-2026-78078, CVE-2026-78079

  • Unrated

    Helix Ultimate (shaper_helixultimate) below 2.1.4-j3sec - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu) - free JoomShaper security patch available

    Affected: < 2.1.4-j3sec

Our coverage

Unpatched JoomShaper security holes, fixed in one click

See which of your sites run Helix Ultimate

Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.

Is a Joomla 3 site hacked right now?

We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.

Audit a Joomla 3 site free