Important information for Joomla 3 site owners! On July 15, 2026, JoomShaper developers released long-awaited security patches for Helix Ultimate, Helix 3, and SP Page Builder, specifically for Joomla 3 sites.

Just six days earlier, JoomShaper had officially announced the end of support for Joomla 3, stating that "regardless of severity, there will be no security patches." However, the company quickly reversed this decision and released the fixes.

This update is critically important for all sites that are not yet able to upgrade to Joomla 5 or 6.

What Was Fixed?

The patches address a range of vulnerabilities that were already being actively exploited by attackers:

  • Open Redirect: the ability to redirect visitors to external resources, used for phishing attacks.
  • Missing CSRF Tokens and Permission Checks: AJAX actions could be executed without authorization, allowing site settings to be modified.
  • XSS Vulnerabilities: injection of malicious JavaScript through media embeds, galleries, Mega Menu, and Layout Builder.
  • File Upload Issues: improved validation — SVG and ICO file uploads are now blocked.
  • Path Traversal: incorrect path validation allowed reading or writing files outside of allowed directories.
  • Missing Permission Checks: for blog image deletion and template settings export.

Which Patches Are Available?

JoomShaper released three separate patches for Joomla 3:

These are security-only patches, with no new features or bug fixes.

Important Warning: Check Your Helix Ultimate Version!

The Helix Ultimate patch only supports versions 2.1.0 — 2.1.3. If you have an older version installed (e.g., 1.1.x or 2.0.x), the patch installation will fail and result in an error.

In this case, the only solution is migration to the latest Joomla version (5 or 6).

How to Install the Patches?

  1. Back up your site and database.
  2. Download the patch for your product:
    • Helix Ultimate and Helix 3 — from GitHub (release j3-security-v1.0.0)
    • SP Page Builder — from the JoomShaper website
  3. In the Joomla administrator panel, go to System → Install → Extensions.
  4. Upload the downloaded .zip file and install it.

What If Your Site Was Already Hacked?

Installing the patch does not remove signs of compromise left before the update. Attackers could have:

  • Created hidden Super Administrator accounts.
  • Injected malicious JavaScript into the Custom JavaScript field in template settings.
  • Uploaded malicious PHP files into SP Page Builder folders.

After installing the patch, be sure to:

  • Check the user list for suspicious administrators.
  • Review template settings (Custom Code, Custom JavaScript).
  • Check the /images and /media folders for any unauthorized PHP files.

Important!
If you are not confident you can check and clean the site yourself — contact us for assistance!

Recommendation

The patches provide temporary relief, but do not solve the main problem: Joomla 3 has not received core updates since August 2023. The only proper solution is migration to Joomla 5 or 6.

If you have the ability — upgrade Joomla to the latest version. If not — install the patches as soon as possible and start planning your migration.