Impact
The Helix Ultimate Joomla extension, available from joomshaper.com, contains an unauthenticated stored cross‑site scripting vulnerability (CWE‑79). The flaw allows an attacker to inject arbitrary JavaScript into data that the extension persists and later displays to site visitors. When executed in a user’s browser, the payload can hijack sessions, deface content, or perform other client‑side attacks. The impact is confined to the victim’s browser session but can compromise the integrity and confidentiality of their data or identity.
Affected Systems
The Helix Ultimate extension for Joomla, released by joomshaper.com, is affected for all versions older than 2.2.7. No other Joomla extensions or the core Joomla platform itself are included in the scope as per the information provided.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity flaw. EPSS is reported as < 1%, which suggests the likelihood of attack discovery and exploitation is low at present, but sites still running vulnerable versions remain at risk. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploits yet, yet the high impact justifies immediate remediation. The attack vector is inferred to be a direct submission of malicious content to the extension’s publicly exposed input fields without authentication.
OpenCVE Enrichment