Hello,
Thank you for sharing the Patchman notifications.
The first alert relates to a Joomla XSS vulnerability in the toolbar link layout, identified as CVE-2026-92224. This affected Joomla 4.0.0–5.4.8 and 6.0.0–6.1.3 and was fixed in Joomla 5.4.9 and 6.1.4. The file detected by Patchman is a Helix Ultimate override of this Joomla layout.
The second alert concerns CVE-2026-48954, an XSS vulnerability in Joomla's Language Overrides feature. This was fixed in Joomla 5.4.7 and 6.1.2.
These alerts do not necessarily indicate that your website has been hacked. They indicate that Patchman detected code associated with known Joomla security vulnerabilities.
We recommend keeping Joomla and Helix Ultimate updated to their latest versions. If Patchman has modified these files, please take a backup and update them through the official Joomla/Helix update mechanisms to ensure the correct files are restored.
Best regards