JoomShaper and Joomla 3
Announced on 9 July 2026 that Joomla 3 would get no security patches regardless of severity, then shipped Joomla 3 security packages for Helix Ultimate, Helix3 and SP Page Builder six days later and kept patching through September.
Joomla extensions covered: Helix Ultimate, Helix3, SP Page Builder. JoomShaper website
What they said
“No security patches, regardless of severity”
Said 9 Jul 2026Read it on their siteChecked 2 Oct 2026
What they did
Joomla 3 security patches ship for Helix Ultimate, Helix3 and SP Page Builder, six days after the no-patches announcement
Helix Ultimate Joomla 3 patch 1.0.1 released
Helix Ultimate J3 Security Fixes 1.0.2 backports most of the 2.2.10 security work, under the unchanged version string 2.1.4-j3sec
Helix Ultimate J3 Security Fixes 1.0.3 closes an authorisation gap mySites.guru reported in 1.0.2
SP Page Builder Joomla 3 patch 1.0.2 ships alongside 6.9.1; mySites.guru reports two gaps in it the same day
SP Page Builder Joomla 3 Security Patch 1.0.3 closes the captcha bypass and the incomplete XSS fix
Known Joomla 3 vulnerabilities
- High
SP Page Builder (com_sppagebuilder) 6.8.0 to 6.9.0 - CVE-2026-78375 Author-level SQL Injection (full database read, CVSS 8.6), CVE-2026-79700 and CVE-2026-79701 Unauthenticated Captcha Bypass, plus three authorisation flaws - fixed in 6.9.1
Affected: ≥ 6.8.0 and < 6.9.1
CVE-2026-78375, CVE-2026-79700, CVE-2026-79701, CVE-2026-81564, CVE-2026-81565, CVE-2026-81566
- Critical
SP Page Builder (com_sppagebuilder) 4.0.0 to 6.6.1 - CVE-2026-48908 (CVSS 10.0) Unauthenticated Arbitrary File Upload (RCE)
Affected: ≥ 4.0.0 and < 6.6.2
- High
Helix Ultimate Framework (helixultimate) 2.2.7 to 2.2.9 - Media Upload Bypass, Path Traversal, Broken Access Control and Stored XSS
Affected: ≥ 2.2.7 and < 2.2.10
CVE-2026-78075, CVE-2026-78076, CVE-2026-78077, CVE-2026-78078, CVE-2026-78079
- Unrated
Helix Ultimate Framework (helixultimate) below 2.1.4-j3sec - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu) - free JoomShaper security patch available
Affected: < 2.1.4-j3sec
- High
Helix Ultimate (shaper_helixultimate) 2.2.7 to 2.2.9 - Media Upload Bypass, Path Traversal, Broken Access Control and Stored XSS
Affected: ≥ 2.2.7 and < 2.2.10
CVE-2026-78075, CVE-2026-78076, CVE-2026-78077, CVE-2026-78078, CVE-2026-78079
- Unrated
Helix Ultimate (shaper_helixultimate) below 2.1.4-j3sec - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu) - free JoomShaper security patch available
Affected: < 2.1.4-j3sec
Our coverage
- SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.
JoomShaper's first Joomla 3 security patch for SP Page Builder left the captcha bypass live and the XSS fix incomplete. Version 1.0.3 closes both.
- SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru
mySites.guru found an Author-level SQL injection and an unauthenticated captcha bypass in the SP Page Builder Joomla extension, both fixed in 6.9.1.
- Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None
JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.
- Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass
Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.
- JoomShaper Patched the Joomla 3 It Said It Never Would
Six days after excluding Joomla 3 security patches, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them.
- The One-Click Way to Patch JoomShaper Extensions on Joomla 3
mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, across every site in your account.
- JoomShaper Ends Joomla 3 Security Fixes
JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches.
See which of your sites run Helix Ultimate
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Is a Joomla 3 site hacked right now?
We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.