Medium severity5.4NVD Advisory· Published Apr 29, 2026· Updated May 1, 2026
CVE-2026-40230
CVE-2026-40230
Description
Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body field of a knowledge base Doc.This issue affects helpy: 2.8.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- fluidattacks.com/es/advisories/prisionerosnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.