Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Helpy.io
Helpy.io helpy |
|
| Vendors & Products |
Helpy.io
Helpy.io helpy |
Wed, 29 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0. | |
| Title | Helpy 2.8.0 - Stored XSS in post author display via PostsHelper | |
| First Time appeared |
Helpyio
Helpyio helpy |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:helpyio:helpy:2.8.0:*:linux:*:*:*:*:* cpe:2.3:a:helpyio:helpy:2.8.0:*:macos:*:*:*:*:* cpe:2.3:a:helpyio:helpy:2.8.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Helpyio
Helpyio helpy |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2026-04-29T15:34:50.094Z
Updated: 2026-04-29T16:20:14.057Z
Reserved: 2026-04-10T16:07:49.030Z
Link: CVE-2026-40229
Updated: 2026-04-29T16:20:10.471Z
Status : Awaiting Analysis
Published: 2026-04-29T16:16:24.213
Modified: 2026-04-30T15:11:12.703
Link: CVE-2026-40229
No data.