๐Ÿ” CVE Alert

CVE-2026-40229

UNKNOWN 0.0

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.

CWE CWE-79
Vendor helpyio
Product helpy
Published Apr 29, 2026
Last Updated Apr 29, 2026
Stay Ahead of the Next One

Get instant alerts for helpyio helpy

Be the first to know when new unknown vulnerabilities affecting helpyio helpy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

helpyio / helpy
2.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fluidattacks.com: https://fluidattacks.com/es/advisories/offspring github.com: https://github.com/helpyio/helpy

Credits

Oscar Uribe Fluid Attacks' AI SAST Scanner