# CVE-2026-78079

## Summary

- **CVE ID:** CVE-2026-78079
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-601
- **Published:** Aug 31, 2026
- **Last Modified:** Sep 1, 2026

## Description

Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.

## Affected Products

- joomshaper.com — Helix Ultimate extension for Joomla (1.0-2.2.9)

## References

- [CNA](https://www.joomshaper.com/joomla-templates/helixultimate)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._