Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body field of a knowledge base Doc.This issue affects helpy: 2.8.0.
References
| Link | Resource |
|---|---|
| https://fluidattacks.com/es/advisories/prisioneros | Exploit Third Party Advisory |
| https://github.com/helpyio/helpy | Product |
Configurations
History
No history.
Information
Published : 2026-04-29 16:16
Updated : 2026-06-17 10:44
NVD link : CVE-2026-40230
Mitre link : CVE-2026-40230
CVE.ORG link : CVE-2026-40230
JSON object : View
Products Affected
helpy.io
- helpy
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
