Megamenu was hacked, database injected - Forum | JoomShaper
Staff replied SP Page Builder

Megamenu was hacked, database injected

Asked by jcalvert 2 months ago Last activity 2 months ago

Hello,

I just encounted one of my websites using SP Page Builder Pro, current version.

The Home page menu link was hacked and JS code injected.

Please contact me asap for details.

4 replies

jcalvert Asked this

OK, this was caused because the JoomShaper template that I'm using uses Helix Ultimate, which also required an update due to CVE-2026-57829. I wasn't aware of that.

My other websites using Helix were not affected, because they are not using Helix Ultimate (not even installed). I had updated to Helix 3.1.2.

PLEASE post a pinned security warning that Helix Ultimate also need to be updated to the current version, 2.2.9. (Vulnerabilities were fixed in vers. 2.2.7, as per the change log).

Ofi Khan Staff

Hello jcalvert,

Thank you for reaching out to our technical support forum. I’m sorry to hear about the trouble you have experienced.

We have already fixed the issues and notified our users. We even solved the issues for old Joomla 3 users too. Please check out this article for details:

Security Update

Best regards

jcalvert Asked this

OK, thanks.

I didn't get any notification about this, which is why I suggested that you create a separate email list that customers can subscribe to, so that they can get security alerts very quickly.

I had no idea about this blog article, https://www.joomshaper.com/blog/security-update-for-joomla-3-users, and I see it was only posted yesterday, July 15th.

I went to this forum for help, so I'm sure other people are doing that, which is why you should link the blog article as a pinned post to the forum, don't you think?

thank you

Ofi Khan Staff

Thank you for your suggestion. I hope the management will consider it.

Log in to reply.