CVE-2026-57829
MEDIUMJoomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-57829. PoCs published by Is4yev.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-57829, an unauthenticated stored XSS vulnerability in the JoomShaper Helix Ultimate Framework (plg_system_helixultimate <= 2.2.6). The exploit demonstrates how an attacker can inject malicious JavaScript into a menu item's custom class, which is then rendered unescaped on every page for all visitors, leading to potential admin session-riding and account takeover.
Description
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2026-57829, an unauthenticated stored XSS vulnerability in the JoomShaper Helix Ultimate Framework (plg_system_helixultimate <= 2.2.6). The exploit demonstrates how an attacker can inject malicious JavaScript into a menu item's custom class, which is then rendered unescaped on every page for all visitors, leading to potential admin session-riding and account takeover.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N