Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 01 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:helpy.io:helpy:2.8.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 30 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Helpy.io
Helpy.io helpy |
|
| Vendors & Products |
Helpy.io
Helpy.io helpy |
Wed, 29 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body field of a knowledge base Doc.This issue affects helpy: 2.8.0. | |
| Title | Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering | |
| First Time appeared |
Helpyio
Helpyio helpy |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:helpyio:helpy:2.8.0:*:linux:*:*:*:*:* cpe:2.3:a:helpyio:helpy:2.8.0:*:macos:*:*:*:*:* cpe:2.3:a:helpyio:helpy:2.8.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Helpyio
Helpyio helpy |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-04-29T16:20:34.028Z
Reserved: 2026-04-10T16:07:49.031Z
Link: CVE-2026-40230
Updated: 2026-04-29T16:20:30.646Z
Status : Analyzed
Published: 2026-04-29T16:16:24.350
Modified: 2026-05-01T12:26:33.710
Link: CVE-2026-40230
No data.
OpenCVE Enrichment
Updated: 2026-04-30T08:15:31Z