CVE-2026-57830
Critical · CVSS 9.1Helix Ultimate (Joomla extension) — Unauthenticated Arbitrary File Deletion (Missing Authorization)
- CVSS
- 9.1
- nvd
- EPSS
- 0.24%
- 16th pct
- KEV
- No
- Class
- other
- CWE-862
Description
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
Search profile — drives PoC discovery
Symbols helix_ultimatehelixultimatefile_deleteunlinkdeleteFilecom_helixultimateHelixUltimate
Keywords CVE-2026-57830Helix UltimateJoomlaarbitrary file deletionunauthenticatedfile deletionCWE-862missing authorizationJoomShaperhelixultimate exploithelixultimate PoC
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 3
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z