VendorsHelpy.iohelpy2.8.0
Vulnerabilities

Helpy.io Helpy 2.8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-0357
Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the ticket.
Published 2023-04-04 · Modified
6.1EPSS 0.007
CVE-2025-52184
Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion.
Published 2025-08-26 · Analyzed
6.1EPSS 0.003
CVE-2026-40230
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
Published 2026-04-29 · Analyzed
5.4EPSS 0.003
CVE-2026-40229
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
Published 2026-04-29 · Analyzed
5.4EPSS 0.003