Unauthenticated Stored XSS Vulnerability in Helix Ultimate Extension by Joomla
CVE-2026-57829
Key Information:
- Vendor
Joomshaper.com
- Vendor
- CVE Published:
- 13 July 2026
Badges
What is CVE-2026-57829?
The Helix Ultimate extension for Joomla contains a vulnerability that allows unauthenticated users to execute malicious scripts on affected installations. This security flaw can result in stored Cross-Site Scripting (XSS) attacks, where an attacker can input harmful code that is stored and executed by the browser of unsuspecting users. Proper security measures should be taken to patch and mitigate this risk to ensure the safety of users and integrity of the web application.
Affected Version(s)
Helix Ultimate extension for Joomla 1.0-2.2.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
