SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-57829

MEDIUM · CVSS 6.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The Helix Ultimate Joomla extension, prior to version 2.2.7, is susceptible to unauthenticated stored cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts that can execute in the context of users accessing the affected site. This could lead to data theft, session hijacking, or defacement of the website. Joomla site administrators using this extension should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-57829
Severity
MEDIUM
CVSS
6.1
EPSS
0.18%

Original NVD Description

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

Related CVEs

Other vulnerabilities affecting the same vendor(s)