VulnerabilityAnalyzed
CVE-2026-40229
Helpy contains a stored cross-site scripting vulnerability in the post author display logic.
MEDIUM 5.1EPSS 0.18%
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.18% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- helpy.io/helpy
- Source
- help@fluidattacks.com
References
- https://fluidattacks.com/es/advisories/offspringExploit, Third Party Advisory
- https://github.com/helpyio/helpyProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.