CVE 5.1 MEDIUM

Helpy 2.8.0 – Stored XSS in post author display via PostsHelper_CVE-2026-40229

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Description

Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.

Basic Information

ID CVE-2026-40229
Source Fluid Attacks
Published Apr 29, 2026 at 15:34
Modified Apr 29, 2026 at 16:20

Affected Product

Vendor helpyio
Product helpy
Version 2.8.0
Affected Versions helpyio helpy 2.8.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.