Description
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
Published: 2026-07-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helix Ultimate Joomla extension, available from joomshaper.com, contains an unauthenticated stored cross‑site scripting vulnerability (CWE‑79). The flaw allows an attacker to inject arbitrary JavaScript into data that the extension persists and later displays to site visitors. When executed in a user’s browser, the payload can hijack sessions, deface content, or perform other client‑side attacks. The impact is confined to the victim’s browser session but can compromise the integrity and confidentiality of their data or identity.

Affected Systems

The Helix Ultimate extension for Joomla, released by joomshaper.com, is affected for all versions older than 2.2.7. No other Joomla extensions or the core Joomla platform itself are included in the scope as per the information provided.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity flaw. EPSS is reported as < 1%, which suggests the likelihood of attack discovery and exploitation is low at present, but sites still running vulnerable versions remain at risk. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploits yet, yet the high impact justifies immediate remediation. The attack vector is inferred to be a direct submission of malicious content to the extension’s publicly exposed input fields without authentication.

Generated by OpenCVE AI on August 4, 2026 at 07:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Helix Ultimate to version 2.2.7 or later.
  • If upgrading is not immediately possible, disable or remove any extension features that accept user input on publicly accessible pages, or replace them with static content.
  • Implement a Content Security Policy to restrict script sources to trusted origins, thereby limiting the effect of any remaining XSS payloads.

Generated by OpenCVE AI on August 4, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS. Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
Title Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ollyo Helix Ultimate
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:55:42.290Z

Reserved: 2026-06-25T16:55:04.094Z

Link: CVE-2026-57829

cve-icon Vulnrichment

Updated: 2026-07-13T14:46:37.595Z

cve-icon NVD

Status : Modified

Published: 2026-07-13T08:16:21.547

Modified: 2026-07-23T16:17:28.497

Link: CVE-2026-57829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')