CVE-2026-40230
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body field of a knowledge base Doc.This issue affects helpy: 2.8.0.
| CWE | CWE-79 |
| Vendor | helpyio |
| Product | helpy |
| Published | Apr 29, 2026 |
| Last Updated | Apr 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for helpyio helpy
Be the first to know when new unknown vulnerabilities affecting helpyio helpy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
helpyio / helpy
2.8.0
References
Credits
Oscar Uribe Fluid Attacks' AI SAST Scanner