Description
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
Published: 2026-07-13
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helix Ultimate Joomla extension, before version 2.2.7, contains an unauthenticated stored cross‑site scripting flaw (CWE‑79). This weakness allows an attacker to embed arbitrary JavaScript into the extension’s input fields, which is then rendered and executed for any user who visits the affected page. The injected script runs in the visitor’s browser context, potentially enabling the attacker to steal session credentials, deface the site, or execute other malicious actions.

Affected Systems

The Helix Ultimate extension for Joomla published by joomshaper.com is affected. Any installation that remains on a version earlier than 2.2.7 is potentially compromised. No other extensions or core Joomla releases are mentioned as affected.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity vulnerability. An attacker can exploit the flaw by submitting malicious content through the extension’s publicly exposed input fields without authentication. Although the EPSS score is below 1 %, suggesting low prior exploitation, sites still running vulnerable versions remain susceptible. The vulnerability is not listed in the CISA KEV catalog, indicating that no confirmed exploitation reports have been released, but the weakness remains actionable if the affected extension is in use.

Generated by OpenCVE AI on July 31, 2026 at 12:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Helix Ultimate extension to version 2.2.7 or later.
  • If an upgrade is not immediately possible, disable or remove any extension features that accept user input on public pages or replace them with static content.
  • Implement a Content Security Policy that restricts script execution to trusted sources to mitigate potential XSS payloads.

Generated by OpenCVE AI on July 31, 2026 at 12:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS. Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
Title Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:55:42.290Z

Reserved: 2026-06-25T16:55:04.094Z

Link: CVE-2026-57829

cve-icon Vulnrichment

Updated: 2026-07-13T14:46:37.595Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')