Helpy.io
Helpy.io Helpy: vulnerabilidades y CVE
Helpy.io Helpy tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40230 | Media (4.8) | 0.26% | — | 29 abr 2026 | Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body… |
| CVE-2026-40229 | Media (5.1) | 0.26% | — | 29 abr 2026 | Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public… |
| CVE-2025-52184 | Media (6.1) | 0.34% | — | 26 ago 2025 | Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion. |
| CVE-2023-0357 | Media (6.1) | 0.69% | — | 4 abr 2023 | Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the… |
| CVE-2018-20851 | Alta (8.8) | 1.5% | — | 10 jul 2019 | Helpy before 2.2.0 allows agents to edit admins. |
| CVE-2018-18886 | Media (6.1) | 0.88% | — | 18 jun 2019 | Helpy v2.1.0 has Stored XSS via the Ticket title. |