CVE-2026-40229 PUBLISHED

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

Assigner: Fluid Attacks
Reserved: 10.04.2026 Published: 29.04.2026 Updated: 29.04.2026

Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor helpyio
Product helpy
Versions Default: unaffected
  • Version 2.8.0 is affected

Credits

  • Oscar Uribe finder
  • Fluid Attacks' AI SAST Scanner finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE

Impacts

  • CAPEC-592 Stored XSS