The number and severity of CVEs published that impact products developed by Ollyo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48908CRITICAL A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | Jun 20, 2026 | 9.8 | 81 | YES | NO |
CVE-2026-57830CRITICAL Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbi | Jul 13, 2026 | 9.1 | 41 | NO | NO |
CVE-2026-49049HIGH The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameter | Jun 29, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-57829MEDIUM Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS. | Jul 13, 2026 | 6.1 | 31 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ollyo.
Media articles that mention a CVE ID that affects a product developed by Ollyo — matched by CVE ID, not by vendor name.