CVE-2026-40229
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.
| CWE | CWE-79 |
| Vendor | helpyio |
| Product | helpy |
| Published | Apr 29, 2026 |
| Last Updated | Apr 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for helpyio helpy
Be the first to know when new unknown vulnerabilities affecting helpyio helpy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
helpyio / helpy
2.8.0
References
Credits
Oscar Uribe Fluid Attacks' AI SAST Scanner