CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-57830

Critical · CVSS 9.1

Helix Ultimate (Joomla extension) — Unauthenticated Arbitrary File Deletion (Missing Authorization)

CVSS
9.1
nvd
EPSS
0.24%
16th pct
KEV
No
Class
other
CWE-862

Description

Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

Search profile — drives PoC discovery

Symbols helix_ultimatehelixultimatefile_deleteunlinkdeleteFilecom_helixultimateHelixUltimate
Keywords CVE-2026-57830Helix UltimateJoomlaarbitrary file deletionunauthenticatedfile deletionCWE-862missing authorizationJoomShaperhelixultimate exploithelixultimate PoC

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z