VendorsHelpy.iohelpyall versions
Vulnerabilities

Helpy.io Helpy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2018-20851
Helpy before 2.2.0 allows agents to edit admins.
Published 2019-07-10 · Modified
8.8EPSS 0.015
CVE-2018-18886
Helpy v2.1.0 has Stored XSS via the Ticket title.
Published 2019-06-18 · Modified
6.1EPSS 0.009
CVE-2023-0357
Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the ticket.
Published 2023-04-04 · Modified
6.1EPSS 0.007
CVE-2025-52184
Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion.
Published 2025-08-26 · Analyzed
6.1EPSS 0.003
CVE-2026-40230
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
Published 2026-04-29 · Analyzed
5.4EPSS 0.003
CVE-2026-40229
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
Published 2026-04-29 · Analyzed
5.4EPSS 0.003