CVE-2026-40229

Source
https://cve.org/CVERecord?id=CVE-2026-40229
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40229.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40229
Published
2026-04-29T15:34:50.094Z
Modified
2026-08-12T03:51:15.925061152Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
Details

Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to other users.This issue affects helpy: 2.8.0.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "Fluid Attacks",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40229.json"
}
References

Affected packages

Git / github.com/helpyio/helpy

Affected ranges

Type
GIT
Repo
https://github.com/helpyio/helpy
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ],
    "extracted_events": [
        {
            "introduced": "2.8.0"
        },
        {
            "last_affected": "2.8.0"
        }
    ],
    "cpe": "cpe:2.3:a:helpy.io:helpy:2.8.0:*:*:*:*:*:*:*"
}

Affected versions

2.*
2.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40229.json"