Table of contents
Important information for Joomla 3 site owners! On July 15, 2026, JoomShaper developers released long-awaited security patches for Helix Ultimate, Helix 3, and SP Page Builder, specifically for Joomla 3 sites.
Just six days earlier, JoomShaper had officially announced the end of support for Joomla 3, stating that "regardless of severity, there will be no security patches." However, the company quickly reversed this decision and released the fixes.
This update is critically important for all sites that are not yet able to upgrade to Joomla 5 or 6.
What Was Fixed?
The patches address a range of vulnerabilities that were already being actively exploited by attackers:
- Open Redirect: the ability to redirect visitors to external resources, used for phishing attacks.
- Missing CSRF Tokens and Permission Checks: AJAX actions could be executed without authorization, allowing site settings to be modified.
- XSS Vulnerabilities: injection of malicious JavaScript through media embeds, galleries, Mega Menu, and Layout Builder.
- File Upload Issues: improved validation — SVG and ICO file uploads are now blocked.
- Path Traversal: incorrect path validation allowed reading or writing files outside of allowed directories.
- Missing Permission Checks: for blog image deletion and template settings export.
Which Patches Are Available?
JoomShaper released three separate patches for Joomla 3:
- Helix Ultimate Security Patch v1.0.0 — for sites running Helix Ultimate (base version 2.1.0–2.1.3). Check if the patch is compatible with your version — see the "Important Warning" section below.
- Helix 3 Security Patch v1.0.0 — updates plugins to version 3.1.2.
- SP Page Builder Security Patch — previously only available for manual installation, now installable through the extension manager.
These are security-only patches, with no new features or bug fixes.
Important Warning: Check Your Helix Ultimate Version!
The Helix Ultimate patch only supports versions 2.1.0 — 2.1.3. If you have an older version installed (e.g., 1.1.x or 2.0.x), the patch installation will fail and result in an error.
In this case, the only solution is migration to the latest Joomla version (5 or 6).
How to Install the Patches?
- Back up your site and database.
- Download the patch for your product:
- Helix Ultimate and Helix 3 — from GitHub (release
j3-security-v1.0.0) - SP Page Builder — from the JoomShaper website
- Helix Ultimate and Helix 3 — from GitHub (release
- In the Joomla administrator panel, go to System → Install → Extensions.
- Upload the downloaded
.zipfile and install it.
What If Your Site Was Already Hacked?
Installing the patch does not remove signs of compromise left before the update. Attackers could have:
- Created hidden Super Administrator accounts.
- Injected malicious JavaScript into the Custom JavaScript field in template settings.
- Uploaded malicious PHP files into SP Page Builder folders.
After installing the patch, be sure to:
- Check the user list for suspicious administrators.
- Review template settings (Custom Code, Custom JavaScript).
- Check the
/imagesand/mediafolders for any unauthorized PHP files.
Recommendation
The patches provide temporary relief, but do not solve the main problem: Joomla 3 has not received core updates since August 2023. The only proper solution is migration to Joomla 5 or 6.
If you have the ability — upgrade Joomla to the latest version. If not — install the patches as soon as possible and start planning your migration.
Terms used:
AJAX, JavaScript, PHP, Menu, Redirect, Helix Ultimate, SP Page Builder