FAIL › dossier
ollyo
VENDOR· dossier confidence 0%
Ollyo is a Joomla extension developer whose products have suffered multiple critical vulnerabilities, including unauthenticated remote code execution and SQL injection, revealing significant gaps in their security development lifecycle and patch management.
PROFILE
Categoryweb-developmentWhat they doOllyo develops Joomla extensions, including Page Builder and Helix Ultimate.
SECURITY POSTURE
The company has a poor security posture, evidenced by critical vulnerabilities in its extensions that were exploited or disclosed within a short timeframe, indicating a lack of robust security testing and patch management processes.
Notable failures
- CVE-2026-48908: Unauthenticated RCE via SP Page Builder for Joomla
- CVE-2026-57830: Unauthenticated arbitrary file execution in Helix Ultimate
- CVE-2026-74254: Critical SQL injection in Page Builder CK
Patterns: repeated critical unauthenticated RCEs and SQLi in Joomla extensions; lack of timely patching for high-severity flaws
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-20 | CVE-2026-48908 | critical | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. |
| 2026-07-13 | CVE-2026-57830 | critical | CVE-2026-57830: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrar |
DOSSIER SOURCES
- Extension developers, it's time to mark your security updates · magazine.joomla.org
- Joomla Extensions: Two Critical SQLi and Two Medium Flaws Disclosed ... · portal.vyprsec.ai
- Joomla! Forum - community, help and support - Index page · forum.joomla.org
Open questions: Are there additional unpatched vulnerabilities in Ollyo's other Joomla extensions? · What is the current patching cadence for Ollyo's extensions?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-21 03:59:35.641502+00:00