Impact
Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious HTML/JS. This stored XSS can run arbitrary JavaScript in the browsers of all visitors who view the affected menu, enabling cookie theft, session hijack, defacement, or other malicious actions. The vulnerability is stored, so it persists and is delivered to any user who accesses the page. The likely attack vector is an administrator or user with edit rights to the Helix Ultimate MegaMenu layout, who injects content that is later rendered for all site visitors.
Affected Systems
The vulnerability affects the JoomShaper Helix Ultimate extension for Joomla. Any installation of Helix Ultimate older than version 2.2.10 is impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity, reflecting the significant impact on confidentiality and integrity for site visitors. EPSS data is unavailable, so the current exploitation probability is unknown, but stored XSS is a common attack mechanism. The vulnerability is not listed in CISA KEV, suggesting no documented active exploitation, yet the required administrator privilege makes it a moderate-to-high risk for sites that allow third‑party content creation.
OpenCVE Enrichment