CVE-2026-57829

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ollyo:helix_ultimate:*:*:*:*:*:joomla\!:*:*

History

23 Jul 2026, 16:17

Type Values Removed Values Added
Summary (en) The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS. (en) Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

14 Jul 2026, 18:22

Type Values Removed Values Added
CPE cpe:2.3:a:ollyo:helix_ultimate:*:*:*:*:*:joomla\!:*:*
First Time Ollyo
Ollyo helix Ultimate
References () https://www.joomshaper.com/joomla-templates/helixultimate - () https://www.joomshaper.com/joomla-templates/helixultimate - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

13 Jul 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 08:16

Updated : 2026-07-23 16:17


NVD link : CVE-2026-57829

Mitre link : CVE-2026-57829

CVE.ORG link : CVE-2026-57829


JSON object : View

Products Affected

ollyo

  • helix_ultimate
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')