CVE-2026-57829: Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7
Published Jul 13, 2026
·Updated
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
Affected Software
2 affected components
joomla/helix-ultimate<2.2.7
Ollyo Helix Ultimate Joomla\!>=1.0<=2.2.6
Event History
Jul 13, 2026
CVE Published
via MITRE·07:28 AM
Data Sourced
via MITRE·07:28 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57829?
CVE-2026-57829 has a high severity rating of 8.7 on the CVSS scale.
2
What type of vulnerability is CVE-2026-57829?
CVE-2026-57829 is an unauthenticated stored Cross-Site Scripting (XSS) vulnerability.
3
How can I fix CVE-2026-57829?
To fix CVE-2026-57829, upgrade the Helix Ultimate extension to version 2.2.7 or later.
4
Who is affected by CVE-2026-57829?
Any Joomla site using the Helix Ultimate extension version lower than 2.2.7 is affected by CVE-2026-57829.
5
What could happen if CVE-2026-57829 is exploited?
If exploited, CVE-2026-57829 can allow attackers to execute arbitrary scripts in the context of users' sessions.