Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 29 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Description Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.
Title Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
First Time appeared Helpyio
Helpyio helpy
Weaknesses CWE-79
CPEs cpe:2.3:a:helpyio:helpy:2.8.0:*:linux:*:*:*:*:*
cpe:2.3:a:helpyio:helpy:2.8.0:*:macos:*:*:*:*:*
cpe:2.3:a:helpyio:helpy:2.8.0:*:windows:*:*:*:*:*
Vendors & Products Helpyio
Helpyio helpy
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-04-29T16:20:14.057Z

Reserved: 2026-04-10T16:07:49.030Z

Link: CVE-2026-40229

cve-icon Vulnrichment

Updated: 2026-04-29T16:20:10.471Z

cve-icon NVD

Status : Received

Published: 2026-04-29T16:16:24.213

Modified: 2026-04-29T16:16:24.213

Link: CVE-2026-40229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses