Impact
The Helix Ultimate Joomla extension, before version 2.2.7, contains an unauthenticated stored cross‑site scripting flaw (CWE‑79). This weakness allows an attacker to embed arbitrary JavaScript into the extension’s input fields, which is then rendered and executed for any user who visits the affected page. The injected script runs in the visitor’s browser context, potentially enabling the attacker to steal session credentials, deface the site, or execute other malicious actions.
Affected Systems
The Helix Ultimate extension for Joomla published by joomshaper.com is affected. Any installation that remains on a version earlier than 2.2.7 is potentially compromised. No other extensions or core Joomla releases are mentioned as affected.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity vulnerability. An attacker can exploit the flaw by submitting malicious content through the extension’s publicly exposed input fields without authentication. Although the EPSS score is below 1 %, suggesting low prior exploitation, sites still running vulnerable versions remain susceptible. The vulnerability is not listed in the CISA KEV catalog, indicating that no confirmed exploitation reports have been released, but the weakness remains actionable if the affected extension is in use.
OpenCVE Enrichment