CVE-2026-78075 | Joomshaper Helix Ultimate Extension up to 2.2.9 Blog Image Deletion Blog::remove_image src improper authorization (EUVD-2026-68529)

SecurityVulns

A vulnerability labeled as problematic has been found in Joomshaper Helix Ultimate Extension up to 2.2.9. Affected is the function Blog::remove_image of the component Blog Image Deletion. Executing a manipulation of the argument src can lead to improper authorization.

This vulnerability is registered as CVE-2026-78075. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More