๐Ÿ” CVE Alert

CVE-2026-40230

UNKNOWN 0.0

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body field of a knowledge base Doc.This issue affects helpy: 2.8.0.

CWE CWE-79
Vendor helpyio
Product helpy
Published Apr 29, 2026
Last Updated Apr 29, 2026
Stay Ahead of the Next One

Get instant alerts for helpyio helpy

Be the first to know when new unknown vulnerabilities affecting helpyio helpy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

helpyio / helpy
2.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
fluidattacks.com: https://fluidattacks.com/es/advisories/prisioneros github.com: https://github.com/helpyio/helpy

Credits

Oscar Uribe Fluid Attacks' AI SAST Scanner